CVE-2012-3132
medium
CVSS v3
—
CVSS v2
6.5
VIR risk
6.5
Description
SQL injection vulnerability in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to execute arbitrary SQL commands via vectors involving CREATE INDEX with a CTXSYS.CONTEXT INDEXTYPE and DBMS_STATS.GATHER_TABLE_STATS.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert_us@oracle.com — https://blogs.oracle.com/security/entry/security_alert_cve_2012_3132
Vendor advisory: secalert_us@oracle.com — http://www.oracle.com/technetwork/topics/security/alert-cve-2012-3132-1721017.html
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| oracle | database_server | 10.2.0.3 | |
| oracle | database_server | 10.2.0.4 | |
| oracle | database_server | 10.2.0.5 | |
| oracle | database_server | 11.1.0.7 | |
| oracle | database_server | 11.2.0.2 | |
| oracle | database_server | 11.2.0.3 | |
References
- http://www.darkreading.com/database-security/167901020/security/news/240004776/hacking-oracle-database-indexes.html
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:150
- http://www.networkworld.com/news/2012/072712-black-hat-shark-bitten-security-researcher-261203.html
- http://www.oracle.com/technetwork/topics/security/alert-cve-2012-3132-1721017.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html
- http://www.securitytracker.com/id?1027367
- http://www.teamshatter.com/topics/general/team-shatter-exclusive/ctxsys-context-privilege-escalation/
- https://blogs.oracle.com/security/entry/security_alert_cve_2012_3132
- http://www.darkreading.com/database-security/167901020/security/news/240004776/hacking-oracle-database-indexes.html
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:150
- http://www.networkworld.com/news/2012/072712-black-hat-shark-bitten-security-researcher-261203.html
- http://www.oracle.com/technetwork/topics/security/alert-cve-2012-3132-1721017.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html
- http://www.securitytracker.com/id?1027367
- http://www.teamshatter.com/topics/general/team-shatter-exclusive/ctxsys-context-privilege-escalation/
- https://blogs.oracle.com/security/entry/security_alert_cve_2012_3132
CWEs
CWE-89
Verify integrity in audit chain (admin only). AS-IS.