DB: Oracle Database Server Workspace Manager Command Injection

This signature detects attempts to exploit a known vulnerability against Oracle Database Server Workspace Manager. A successful attack can lead to arbitrary command injection.

Extended Description

Oracle has released the October 2008 critical patch update addressing 36 vulnerabilities affecting the following software: Oracle Database Oracle Application Server Oracle E-Business Suite Oracle PeopleSoft Enterprise PeopleTools Oracle PeopleSoft Enterprise Oracle JD Edwards EnterpriseOne Tools Oracle WebLogic Server (formerly BEA WebLogic Server) Oracle Workshop for WebLogic (formerly BEA WebLogic Workshop)

Affected Products

Bea_systems weblogic_server

Short Name
DB:ORACLE:WORKSPACE-MGR-INJ
Severity
Major
Recommended
False
Recommended Action
Drop
Category
DB
Keywords
CVE-2008-3982 CVE-2008-3983 CVE-2008-3984 Command Database Injection Manager Oracle Server Workspace bid:31683
Release Date
07/08/2009
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3729
False Positive
Unknown
Vendors

Oracle

Bea_systems

CVSS Score

5.5

Found a potential security threat?