Oracle Application Express (Apex) Unspecified Issues (pre 2.2.1)

This script is Copyright (C) 2013-2015 Recx Ltd.


Synopsis :

The remote host is running a vulnerable version of Oracle Apex.

Description :

There are unspecified vulnerabilities in versions prior to version
2.2.1 of the Oracle Application Express component of the Oracle
Database. The updated version of Apex contains '35 new security fixes
for Oracle Application Express, 25 of which may be remotely
exploitable without authentication'.

See also :

http://www.oracle.com/technetwork/developer-tools/apex/index.html
http://www.oracle.com/technetwork/topics/security/cpuoct2006-095368.html

Solution :

Upgrade Application Express to at least version 2.2.1.

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 8.3
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true

Family: Web Servers

Nessus Plugin ID: 64714 ()

Bugtraq ID: 20588

CVE ID: CVE-2006-5351
CVE-2006-5352

Ready to Scan Unlimited IPs & Run Compliance Checks?

Upgrade to Nessus Professional today!

Buy Now

Combine the Power of Nessus with the Ease of Cloud

Start your free Nessus Cloud trial now!

Begin Free Trial