// For flags

CVE-2006-0586

Oracle 10g - SYS.KUPV$FT.ATTACH_JOB PL / SQL Injection

Severity Score

7.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

3
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple SQL injection vulnerabilities in Oracle 10g Release 1 before CPU Jan 2006 allow remote attackers to execute arbitrary SQL commands via multiple parameters in (1) ATTACH_JOB, (2) HAS_PRIVS, and (3) OPEN_JOB functions in the SYS.KUPV$FT package; and (4) UPDATE_JOB, (5) ACTIVE_JOB, (6) ATTACH_POSSIBLE, (7) ATTACH_TO_JOB, (8) CREATE_NEW_JOB, (9) DELETE_JOB, (10) DELETE_MASTER_TABLE, (11) DETACH_JOB, (12) GET_JOB_INFO, (13) GET_JOB_QUEUES, (14) GET_SOLE_JOBNAME, (15) MASTER_TBL_LOCK, and (16) VALID_HANDLE functions in the SYS.KUPV$FT_INT package. NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that these issues has been addressed by Oracle. It is unclear which, if any, Oracle Vuln# identifiers apply to these issues.

Múltiples vulnerabilidades de inyección SQL en Oracle 10g Release 1 en versiones anteriores a CPU de Enero de 2006 permiten a atacantes remotos ejecutar comandos SQL arbitrarios a través de parámetros múltiples en funciones (1) ATTACH_JOB, (2) HAS_PRIVS y (3) OPEN_JOB en el paquete SYS.KUPV$FT; y funciones (4) UPDATE_JOB, (5) ACTIVE_JOB, (6) ATTACH_POSSIBLE, (7) ATTACH_TO_JOB, (8) CREATE_NEW_JOB, (9) DELETE_JOB, (10) DELETE_MASTER_TABLE, (11) DETACH_JOB, (12) GET_JOB_INFO, (13) GET_JOB_QUEUES, (14) GET_SOLE_JOBNAME, (15) MASTER_TBL_LOCK y (16) VALID_HANDLE en el paquete SYS.KUPV$FT_INT. NOTA: debido a la falta de detalles relevantes en la recomendación de Oracle, se está creando una CVE separada ya que no se puede probar concluyentemente que estas cuestiones hayan sido dirigidas por Oracle. No está claro cuáles, si es que hay alguno, de los identificadores de Oracle Vuln# se aplican a este caso.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2006-02-08 CVE Reserved
  • 2006-02-08 CVE Published
  • 2007-01-23 First Exploit
  • 2023-12-29 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Oracle
Search vendor "Oracle"
Application Server
Search vendor "Oracle" for product "Application Server"
10.1.0.2
Search vendor "Oracle" for product "Application Server" and version "10.1.0.2"
-
Affected
Oracle
Search vendor "Oracle"
Application Server
Search vendor "Oracle" for product "Application Server"
10.1.0.3
Search vendor "Oracle" for product "Application Server" and version "10.1.0.3"
-
Affected
Oracle
Search vendor "Oracle"
Application Server
Search vendor "Oracle" for product "Application Server"
10.1.0.3.1
Search vendor "Oracle" for product "Application Server" and version "10.1.0.3.1"
-
Affected
Oracle
Search vendor "Oracle"
Application Server
Search vendor "Oracle" for product "Application Server"
10.1.0.4
Search vendor "Oracle" for product "Application Server" and version "10.1.0.4"
-
Affected
Oracle
Search vendor "Oracle"
Application Server
Search vendor "Oracle" for product "Application Server"
10.1.2
Search vendor "Oracle" for product "Application Server" and version "10.1.2"
-
Affected
Oracle
Search vendor "Oracle"
Application Server
Search vendor "Oracle" for product "Application Server"
10.1.2.0.1
Search vendor "Oracle" for product "Application Server" and version "10.1.2.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Application Server
Search vendor "Oracle" for product "Application Server"
10.1.2.0.2
Search vendor "Oracle" for product "Application Server" and version "10.1.2.0.2"
-
Affected
Oracle
Search vendor "Oracle"
Application Server
Search vendor "Oracle" for product "Application Server"
10.1.2.1.0
Search vendor "Oracle" for product "Application Server" and version "10.1.2.1.0"
-
Affected
Oracle
Search vendor "Oracle"
Oracle10g
Search vendor "Oracle" for product "Oracle10g"
enterprise_10.1.0.2
Search vendor "Oracle" for product "Oracle10g" and version "enterprise_10.1.0.2"
-
Affected
Oracle
Search vendor "Oracle"
Oracle10g
Search vendor "Oracle" for product "Oracle10g"
enterprise_10.1.0.3
Search vendor "Oracle" for product "Oracle10g" and version "enterprise_10.1.0.3"
-
Affected
Oracle
Search vendor "Oracle"
Oracle10g
Search vendor "Oracle" for product "Oracle10g"
enterprise_10.1.0.3.1
Search vendor "Oracle" for product "Oracle10g" and version "enterprise_10.1.0.3.1"
-
Affected
Oracle
Search vendor "Oracle"
Oracle10g
Search vendor "Oracle" for product "Oracle10g"
enterprise_10.1.0.4
Search vendor "Oracle" for product "Oracle10g" and version "enterprise_10.1.0.4"
-
Affected
Oracle
Search vendor "Oracle"
Oracle10g
Search vendor "Oracle" for product "Oracle10g"
personal_10.1.0.2
Search vendor "Oracle" for product "Oracle10g" and version "personal_10.1.0.2"
-
Affected
Oracle
Search vendor "Oracle"
Oracle10g
Search vendor "Oracle" for product "Oracle10g"
personal_10.1.0.3
Search vendor "Oracle" for product "Oracle10g" and version "personal_10.1.0.3"
-
Affected
Oracle
Search vendor "Oracle"
Oracle10g
Search vendor "Oracle" for product "Oracle10g"
personal_10.1.0.4
Search vendor "Oracle" for product "Oracle10g" and version "personal_10.1.0.4"
-
Affected
Oracle
Search vendor "Oracle"
Oracle10g
Search vendor "Oracle" for product "Oracle10g"
personal_10.10.3.1
Search vendor "Oracle" for product "Oracle10g" and version "personal_10.10.3.1"
-
Affected
Oracle
Search vendor "Oracle"
Oracle10g
Search vendor "Oracle" for product "Oracle10g"
standard_10.1.0.2
Search vendor "Oracle" for product "Oracle10g" and version "standard_10.1.0.2"
-
Affected
Oracle
Search vendor "Oracle"
Oracle10g
Search vendor "Oracle" for product "Oracle10g"
standard_10.1.0.3
Search vendor "Oracle" for product "Oracle10g" and version "standard_10.1.0.3"
-
Affected
Oracle
Search vendor "Oracle"
Oracle10g
Search vendor "Oracle" for product "Oracle10g"
standard_10.1.0.3.1
Search vendor "Oracle" for product "Oracle10g" and version "standard_10.1.0.3.1"
-
Affected
Oracle
Search vendor "Oracle"
Oracle10g
Search vendor "Oracle" for product "Oracle10g"
standard_10.1.0.4
Search vendor "Oracle" for product "Oracle10g" and version "standard_10.1.0.4"
-
Affected
Oracle
Search vendor "Oracle"
Oracle10g
Search vendor "Oracle" for product "Oracle10g"
standard_10.1.0.4.2
Search vendor "Oracle" for product "Oracle10g" and version "standard_10.1.0.4.2"
-
Affected
Oracle
Search vendor "Oracle"
Oracle10g
Search vendor "Oracle" for product "Oracle10g"
standard_10.1.0.5
Search vendor "Oracle" for product "Oracle10g" and version "standard_10.1.0.5"
-
Affected