-----BEGIN PGP SIGNED MESSAGE-----
Team SHATTER Security Advisory
SQL Injection in Oracle Database (DBMS_DEFER_SYS.DELETE_TRAN)
August 4, 2008
Oracle Database Server versions 9iR1, 9iR2, 10gR1, 10gR2 and 11gR1
Yes (Authentication to Database Server is needed)
This vulnerability was discovered and researched by Esteban Mart=EDnez
Fay=F3 of Application Security Inc.
The PL/SQL package DBMS_DEFER_SYS owned by SYS has an instance of SQL
Injection in the DELETE_TRAN procedure. A malicious user can call the
vulnerable procedure of this package with specially crafted parameters
and execute SQL statements with the elevated privileges of SYS user.
Any Oracle database user with EXECUTE privilege on the package
SYS.DBMS_DEFER_SYS can exploit this vulnerability. By default, users
granted DBA have the required privilege. Exploitation of this
vulnerability allows an attacker to execute SQL commands with SYS
Vendor was contacted and a patch was released.
Restrict access to the SYS.DBMS_DEFER_SYS package.
Apply Oracle Critical Patch Update July 2008 available at Oracle Metalink.
Vendor Notification - 9/24/2007
Vendor Response - 9/28/2007
Fix - 7/15/2008
Public Disclosure - 7/23/2008
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (MingW32)
-----END PGP SIGNATURE-----