VDB
CVE-2006-5340
CVE-2006-5340
PUBLISHED
CVSS 7.099999904632568 HIGH
Multiple unspecified vulnerabilities in Oracle Spatial component in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.2 have unknown impact and remote authenticated attack vectors related to (1) mdsys.sdo_lrs, aka Vuln# DB13, and (2) Vuln# DB17. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB13 is related to bypassing input validation for SQL injection related to convert_to_lrs_layer and dbms_assert, and DB17 is related to SQL injection in the trigger in the SDO_DROP_USER package.
EPSS 2.77% · 86.3th percentile
Risk Scores
CVSS 2.0
7.099999904632568
EPSS Score
2.77%
86.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | * |
| oracle | database_server | 8.1.7.4, 9.0.1.5, 9.2.0.7 |
Timeline
- CVE Published
- Feb 4, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 14, 2023 EPSS Score
- Aug 21, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
References
- http://www.red-database-security.com/advisory/oracle_cpu_oct_2006.html url
- 20588 vdb
- 20060726 Bypassing Oracle dbms_assert mailing-list
- HPSBMA02133 vendor-advisory
- http://www.oracle.com/technetwork/topics/security/cpuoct2006-095368.html url
- http://www.databasesecurity.com/oracle/OracleOct2006-CPU-Analysis.pdf url
- http://www.red-database-security.com/wp/bypass_dbms_assert.pdf url
- 20061018 Analysis of the Oracle October 2006 Critical Patch Update mailing-list
- ADV-2006-4065 vdb
- 22396 third-party-advisory
- 1017077 vdb
- 20061023 SQL Injection in Oracle package MDSYS.SDO_LRS mailing-list
- 20060726 Re: Bypassing Oracle dbms_assert mailing-list
- TA06-291A third-party-advisory
- VU#869292 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2006-5340 advisory