Description
SQL injection vulnerability in the SYS.DBMS_CDC_IPUBLISH.CREATE_SCN_CHANGE_SET procedure in Oracle Database Server 10g allows remote attackers to execute arbitrary SQL commands via the CHANGE_SET_NAME parameter.
Product(s):
- Oracle Database Server 10g 10.1.0.2
- Oracle Database Server 10g 10.1.0.3.1
- Oracle Database Server 10g 10.1.0.3
- Oracle Database Server 10g 10.1.0.3 Release 1
- Oracle Database Server 10g 10.1.0.4
- Oracle Database Server 10g 10.1.0.4 Release 1
Question to Ask Vendors:
- Can you confirm whether your systems are affected by CVE-2005-1197, and if so, what steps are you currently taking to mitigate this vulnerability?
- What is your estimated timeline for fully resolving CVE-2005-1197 in your products or services, and how will you communicate updates on this issue to us as your customer?
Recommended Actions:
- Check out the advisory links provided below.