Oracle.Database.Win32.OS.Command.Injection

description-logoDescription

This indicates an attack attempt to exploit a Command Injection Vulnerability in Oracle Database.
The vulnerability is due to insufficient validation when handling user-supplied inputs. A remote attacker could exploit this vulnerability by sending a maliciously crafted request to the target server. Successful exploitation can lead to arbitrary command execution within the context of the system.

affected-products-logoAffected Products

Oracle Database 10g
Oracle Database 9i

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Currently we are not aware of any solution or patch about this vulnerability.

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Status Detail
2024-07-17 28.828
Modified
Name:Oracle.
Database.
Win32.
OS.
Command.
Execution:Oracle.
Database.
Win32.
OS.
Command.
Injection
2024-07-16 28.827
Modified
Name:Oracle.
Win32.
OS.
Command.
Execution:Oracle.
Database.
Win32.
OS.
Command.
Execution