Oracle Database (January 2006 CPU)

This script is Copyright (C) 2011-2014 Tenable Network Security, Inc.


Synopsis :

The remote database server is affected by multiple vulnerabilities.

Description :

The remote Oracle database server is missing the January 2006
Critical Patch Update (CPU) and therefore is potentially affected by
security issues in the following components :

- Advanced Queuing

- Change Data Capture

- Connection Manager

- Data Pump

- Data Pump Metadata API

- Dictionary

- Java Net

- Net Foundation Layer

- Net Listener

- Network Communications (RPC)

- Oracle HTTP Server

- Oracle Label Security

- Oracle Text

- Oracle Workflow Cartridge

- Program Interface Network

- Protocol Support

- Query Optimizer

- Reorganize Objects & Convert Tablespace

- Security

- Streams Apply

- Streams Capture

- Streams Subcomponent

- TDE Wallet

- Upgrade & Downgrade

- XML Database

See also :

http://www.nessus.org/u?aa1ddec6

Solution :

Apply the appropriate patch according to the January 2006 Oracle
Critical Patch Update advisory.

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 8.3
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true