Products
Repscan 2008
PLSQL-Scanner
Hedgehog Enterprise
Checkpwd (free)

Services
Oracle Audit / Hardening
Security Training
Consulting

Information
Published Alerts
Upcoming Alerts
Patch Information
Whitepaper
Presentations
Oracle Fact Sheets
Exploits
Videos
Scripts

News & Events
Events
News

Company
Blog
Contact
People
Partner
Impressum
Sitemap


Search



Search Red-Database-Security

Upcoming Oracle Security Alerts RSS Upcoming Alerts



The following security issues are already reported to the vendors:



Oracle



Oracle BugID

Component

Reported

Severity

10213261 Oracle Database 9.2.0.1-10.2.0.3 4-jul-2007 critical
10074515 Oracle Database 10.2.0.3 11-jun-2007 high
10051649 Oracle Database 10.2.0.3 6-jun-2007 high
10051851 Oracle Database 10.2.0.3 6-jun-2007 high
10051597 Oracle Database 10.2.0.3 6-jun-2007 high
10051595 Oracle Database 10.2.0.3 6-jun-2007 high
10051279 Oracle Database 10.2.0.3 6-jun-2007 high
10051283 Oracle Database 10.2.0.3 6-jun-2007 high
10051215 Oracle Database 10.2.0.3 6-jun-2007 high
10051049 Oracle Database 10.2.0.3 6-jun-2007 high
9944105 Oracle Database (FH) 21-may-2007 high
9948643 Oracle Database (FH) 21-may-2007 high
9866459 Oracle APEX 3.0 8-may-2007 high
9866457 Oracle APEX 3.0 7-may-2007 high
9668765 Oracle Database 4-apr-2007 high
9668601 Oracle Database 4-apr-2007 medium
9668249 Oracle Database 4-apr-2007 medium
9675443 Oracle Database 2-apr-2007 high
9675563 Oracle Database 2-apr-2007 high
9675681 Oracle Database 2-apr-2007 high
9675691 Oracle Database 2-apr-2007 high
9675695 Oracle Database 2-apr-2007 high
9675857 Oracle Database 2-apr-2007 high
9675859 Oracle Database 2-apr-2007 high
9566869 Oracle Database Vault 22-mar-2007 medium
9566967 Oracle Enterprise Manager 22-mar-2007 medium
9566967z Oracle mod_plsql 17-feb-2007 medium
9313701 Oracle Portal 17-feb-2007 low
8023399 Oracle Database 10-jul-2006 high
7520291 Oracle Database 19-apr-2006 high
6543483 Documentation bug concerning a special privilege
4-nov-2005 low
6543923 default role with a dangerous privilege
4-nov-2005 high
6980733 Oracle Database 01-nov-2005 high
6980737 Oracle Database 01-nov-2005 high
6980765 Oracle Database 01-nov-2005 high
6980781 Oracle Database 01-nov-2005 high
6980783 Oracle Database 01-nov-2005 high
6980793 Oracle Database 01-nov-2005 high
6980797 Oracle Database 01-nov-2005 high
6980807 Oracle Database 01-nov-2005 high
6980813 Oracle Database 01-nov-2005 high
6980817 Oracle Database 01-nov-2005 high
6980819 Oracle Database 01-nov-2005 high
6980825 Oracle Database 01-nov-2005 high
6454409 Oracle TNS Listener 10g 19-oct-2005 high
5448895 Oracle Import 09-may-2005 high
2005-S072E Workflow 14-feb-2005 low
2005-S071E Workflow 14-feb-2005 low
2005-S067E JDeveloper 14-feb-2005 medium
2005-S066E JDeveloper 14-feb-2005 medium
2005-S064E Oracle Developer Tools for Visual Studio .NET 12-feb-2005 low
2005-S050E Oracle Database 10g 04-feb-2005 medium
2004-S038E Oracle Database 10g 09-feb-2004 low
2004-S037E Oracle Database 10g 09-feb-2004 low
2004-S034E Oracle Database 10g 09-feb-2004 low
2003-S198E TNS Listener 17-dec-2003 low
2003-S110E Oracle Database 8i/9i 30-oct-2003 low
6085687 Oracle Reports 28-oct-2003 low


Other Vendors



Vendor

RDS BugID

Component

Reported

Severity

OpenBC AKSEC2005-059 OpenBC Outlook Assistent 12-mar-2005 low
Embarcadero AKSEC2005-051 DBArtisan 12-feb-2005 medium
Embarcadero AKSEC2005-050 DBArtisan 12-feb-2005 low
Embarcadero AKSEC2005-049 DBArtisan 12-feb-2005 low


Related Information



History

  • 6-jun-2007 - new bugs added
  • 4-jul-2007 - new bugs added
  • 17-apr-2007 - fixed bugs from the Oracle CPU April 2007 removed
  • 16-jan-2007 - fixed bugs from the Oracle CPU January 2007 removed
  • 18-oct-2006 - fixed bugs from the Oracle CPU October 2006 removed
  • 18-jul-2006 - fixed bugs from the Oracle CPU July 2006 removed
  • 23-jan-2006 - Bugids for the november bugs added
  • 17-jan-2006 - Information concerning Oracle CPU January 2006
  • 09-jan-2006 - RSS Feed added
  • 10-nov-2005 - Clarification concerning the 25 vulnerabilities and the several SQL Injection vulnerabilities
  • 8-oct-2005 - New layout


© 2005-2007 by Red-Database-Security GmbH - last update: 5-jul-2007

Oracle Patch Policy

Vulnerability Fixing Order of Oracke Vulnerabilities

  • Main line of Code
  • New Products (e.g. 10g Rel. 2)
  • Patchsets for older products (e.g. 9.2.0.7)
  • Critical Patch Update

More information available on Oracle OTN:

Security Vulnerability Fixing Policy and Process