Rule Category

SERVER-ORACLE -- Snort has detected traffic exploiting vulnerabilities in Oracle Database Server.

Alert Message

SERVER-ORACLE DBMS_EXPORT_EXTENSION.GET_V2_DOMAIN_INDEX_TABLES access attempt

Rule Explanation

Multiple unspecified vulnerabilities in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and other versions have unknown impact and attack vectors in the (1) Advanced Replication component, as identified by Vuln# DB01, and (2) Oracle Spatial component, as identified by Vuln# DB10. NOTE: details are unavailable from Oracle, but as of 20060421, they have not publicly disputed a claim by a reliable independent researcher that states that DB01 is an unknown issue in the DBMS_REPUTIL package, and DB10 is SQL injection in the INSERT_CATALOG, UPDATE_CATALOG, and DELETE_CATALOG functions of the SDO_CATALOG package. Impact: CVSS base score 9.7 CVSS impact score 9.5 CVSS exploitability score 10.0 confidentialityImpact PARTIAL integrityImpact COMPLETE availabilityImpact COMPLETE Details: Ease of Attack:

What To Look For

No information provided

Known Usage

No public information

False Positives

No known false positives

Contributors

Talos research team. This document was generated from data supplied by the national vulnerability database, a product of the national institute of standards and technology. For more information see [nvd].

Rule Groups

No rule groups

CVE

Rule Vulnerability

CVE Additional Information

This product uses data from the NVD API but is not endorsed or certified by the NVD.
CVE-2006-1866
Loading description
CVE-2006-1867
Loading description
CVE-2006-1868
Loading description
CVE-2006-1869
Loading description
CVE-2006-1870
Loading description
CVE-2006-1871
Loading description
CVE-2006-1872
Loading description
CVE-2006-1873
Loading description
CVE-2006-1874
Loading description
CVE-2006-1875
Loading description
CVE-2006-1876
Loading description
CVE-2006-1877
Loading description
CVE-2006-1879
Loading description
CVE-2006-1880
Loading description
CVE-2006-1881
Loading description
CVE-2006-1882
Loading description
CVE-2006-1883
Loading description
CVE-2006-1884
Loading description
CVE-2006-1885
Loading description
CVE-2006-1886
Loading description
CVE-2006-1887
Loading description