CVE-2006-0547 (CNNVD-200602-060)
中文标题:
Oracle Database AUTH_ALTER_SESSION属性安全绕过和任意SQL语句执行漏洞
英文标题:
Oracle Database 8i, 9i, and 10g allow remote authenticated users to execute arbitrary SQL statements...
漏洞描述
中文描述:
Oracle Database 8i、9i 和 10g 使得远程认证用户可以借助AUTH_ALTER_SESSION属性(已在透明网络底层(TNS)协议身份验证阶段经过修改)在使用SYS用户以及绕过审核记录的情况下执行任意SQL语句(包括新建授权数据库帐号的语句)。
英文描述:
Oracle Database 8i, 9i, and 10g allow remote authenticated users to execute arbitrary SQL statements in the context of the SYS user and bypass audit logging, including statements to create new privileged database accounts, via a modified AUTH_ALTER_SESSION attribute in the authentication phase of the Transparent Network Substrate (TNS) protocol. NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this issue has been addressed by Oracle. It is possible that this is the same issue as Oracle Vuln# DB18 from the January 2006 CPU, in which case this would be subsumed by CVE-2006-0265.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| oracle | database_server | 8.1.7.4 | - | - |
cpe:2.3:a:oracle:database_server:8.1.7.4:r3:*:*:*:*:*:*
|
| oracle | database_server | 9.2.0.6 | - | - |
cpe:2.3:a:oracle:database_server:9.2.0.6:r2:*:*:*:*:*:*
|
| oracle | database_server | 9.2.0.7 | - | - |
cpe:2.3:a:oracle:database_server:9.2.0.7:r2:*:*:*:*:*:*
|
| oracle | database_server | 10.1.0.3 | - | - |
cpe:2.3:a:oracle:database_server:10.1.0.3:r1:*:*:*:*:*:*
|
| oracle | database_server | 10.1.0.4 | - | - |
cpe:2.3:a:oracle:database_server:10.1.0.4:r1:*:*:*:*:*:*
|
| oracle | database_server | 10.1.0.5 | - | - |
cpe:2.3:a:oracle:database_server:10.1.0.5:r1:*:*:*:*:*:*
|
| oracle | database_server | 10.2.0.1 | - | - |
cpe:2.3:a:oracle:database_server:10.2.0.1:r2:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
CVSS评分详情
AV:N/AC:L/Au:N/C:P/I:P/A:P
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2006-0547 |
2025-11-11 15:17:39 | 2025-11-11 07:32:31 |
| NVD | nvd_CVE-2006-0547 |
2025-11-11 14:51:47 | 2025-11-11 07:41:17 |
| CNNVD | cnnvd_CNNVD-200602-060 |
2025-11-11 15:08:50 | 2025-11-11 07:49:04 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 授权问题
- cnnvd_id: 未提取 -> CNNVD-200602-060
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.HIGH
- cvss_score: 未提取 -> 7.5
- cvss_vector: NOT_EXTRACTED -> AV:N/AC:L/Au:N/C:P/I:P/A:P
- cvss_version: NOT_EXTRACTED -> 2.0
- affected_products_count: 0 -> 7
- data_sources: ['cve'] -> ['cve', 'nvd']