CVE-2006-1866
Multiple unspecified vulnerabilities in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and other versions have unknown impact and attack vectors in the (1) Advanced Replication component, as identified by Vuln# DB01, and (2) Oracle Spatial…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.86%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple unspecified vulnerabilities in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and other versions have unknown impact and attack vectors in the (1) Advanced Replication component, as identified by Vuln# DB01, and (2) Oracle Spatial component, as identified by Vuln# DB10. NOTE: details are unavailable from Oracle, but as of 20060421, they have not publicly disputed a claim by a reliable independent researcher that states that DB01 is an unknown issue in the DBMS_REPUTIL package, and DB10 is SQL injection in the INSERT_CATALOG, UPDATE_CATALOG, and DELETE_CATALOG functions of the SDO_CATALOG package.
- CVSS 2.0
- 9.7 HIGHAV:N/AC:L/Au:N/C:P/I:C/A:C
- EPSS
- 4.86% probability · 92th percentile
- CISA KEV
- Not listed
- Affected
- oracle/database server
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/19712Patch, Vendor Advisory
- http://secunia.com/advisories/19859Vendor Advisory
- http://securitytracker.com/id?1015961Patch
- http://www.kb.cert.org/vuls/id/139049US Government Resource
- http://www.oracle.com/technetwork/topics/security/cpuapr2006-090826.html
- http://www.red-database-security.com/advisory/oracle_cpu_apr_2006.html
- http://www.securityfocus.com/archive/1/432267/100/0/threaded
- http://www.securityfocus.com/bid/17590Exploit
- http://www.us-cert.gov/cas/techalerts/TA06-109A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2006/1397Vendor Advisory
- http://www.vupen.com/english/advisories/2006/1571Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26050
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26054
- http://secunia.com/advisories/19712Patch, Vendor Advisory
- http://secunia.com/advisories/19859Vendor Advisory
- http://securitytracker.com/id?1015961Patch
- http://www.kb.cert.org/vuls/id/139049US Government Resource
- http://www.oracle.com/technetwork/topics/security/cpuapr2006-090826.html
- http://www.red-database-security.com/advisory/oracle_cpu_apr_2006.html
- http://www.securityfocus.com/archive/1/432267/100/0/threaded
- http://www.securityfocus.com/bid/17590Exploit
- http://www.us-cert.gov/cas/techalerts/TA06-109A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2006/1397Vendor Advisory
- http://www.vupen.com/english/advisories/2006/1571Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26050
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26054
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.