DB: Oracle Database Trigger MDSYS.SDO_TOPO_DROP_FTBL SQL Injection

This signature detects attempts to exploit a known vulnerability in Oracle Database MDSYS. A successful attack can allow an attacker to insert or remove data from a database. Valid authentication credentials are required to exploit this vulnerability.

Extended Description

Oracle has released the January 2009 critical patch update. The update addresses 41 vulnerabilities affecting the following software: Oracle Database Oracle Secure Backup Oracle TimesTen In-Memory Database Oracle Application Server Oracle Collaboration Suite Oracle E-Business Suite Release Oracle Enterprise Manager Grid Control PeopleSoft Enterprise HRMS JD Edwards Tools Oracle WebLogic Server (formerly BEA WebLogic Server) Oracle WebLogic Portal (formerly BEA WebLogic Portal)

Affected Products

Bea_systems weblogic_server

Short Name
DB:ORACLE:SDO_TOPO_DROP_FTBL
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
DB
Keywords
CVE-2008-3979 Database Injection MDSYS.SDO_TOPO_DROP_FTBL Oracle SQL Trigger bid:33177
Release Date
02/26/2009
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Oracle

Bea_systems

CVSS Score

5.5

Found a potential security threat?