Services
Information
Company |
SQL Injection in package XDB.DBMS_XDBZ0
Details The package XDB.DBMS_XDBZ0 contains SQL injection vulnerabilities in the procedure enable_hierarchy_internal [DB01], disable_hierarchiy_internal [DB15]. Oracle fixed this problem by using bind variables and verifying table names. Patch Information Apply the patches for Oracle CPU October 2006. History 1-nov-2005 Oracle secalert was informed about both bugs. 18-oct-2006 Oracle published CPU October 2006 [DB01], [DB15] 18-oct-2006 Advisory published 23-oct-2006 CVE added © 2006 by Red-Database-Security GmbH - last update 23-oct-2006 |