New Oracle Vulnerabilities in Reporting Tools
US-Cert has highlighted a number of new vulnerabilities in Oracle and DBAs or system administrators should apply the latest security updates.
US-CERT Oracle Vulnerability Advisories
Red Hat Oracle Security Alerts - Published Oracle Security Alerts
19-jul-2005 - Advisory: Various Cross-Site-Scripting Vulnerabilities in Oracle Report - [Various CSS in Oracle Reports] (Not fixed after 718 days)
19-jul-2005 - Advisory: Read parts of any XML-file on the application server via Oracle Report - [Read parts of any XML file via Oracle Reports](Not fixed after 693 days)
19-jul-2005 - Advisory: Read parts of any file on the application server via Oracle Report - [Read parts of any file via Oracle Reports] (Not fixed after 692 days)
19-jul-2005 - Advisory: Overwrite any file on the application server via Oracle Report - [Overwrite files via Oracle Reports] (Not fixed after 706 days)
19-jul-2005 - Advisory: Run any OS Command via uploaded Oracle Report from any directory- [Run any OS command via Oracle Reports] (Not fixed after 663 days)
19-jul-2005 - Advisory: Run any OS Command via uploaded Oracle Forms from any directory- [Run any OS command via Oracle Forms] (Not fixed after 664 days)
Latest Oracle Security Updates - July 2005