Re: [Full-disclosure] ZDI-08-088: Oracle E-Business Suite Self-Service Web Applications SQL Injection Vulnerability

2008-12-16 Thread Integrigy Alerts
The Zero Day Initiative advisory ZDI-08-088 has several inaccuracies. Oracle actually fixed this vulnerability as part of the April 2007 Critical Patch Update and subsequently in ATG_PF.H RUP5 and later. The vulnerability is a serious SQL injection bug in a Self-Service Web Application database

[Full-disclosure] Oracle Jinitiator 1.1.8 Vulnerabilities CVE-2007-4467 - Additional Information

2007-09-12 Thread Integrigy Alerts
US-CERT released an advisory on August 28, 2007 regarding multiple stack buffer overflows in the Oracle Jinitiator product (Vulnerability Note VU#474433/CVE-2007-4467). Due to limited public technical information on Jinitiator, no access to the Oracle support website, and maybe lack of

[Full-disclosure] Oracle E-Business Suite Vulnerability Information April 2007

2007-04-18 Thread Integrigy Alerts
Integrigy has released additional information on the Oracle E-Business Suite 11i and R12 security vulnerabilities in the April 2007 Oracle Critical Patch Update. This analysis includes details (type, impact, etc.) regarding the vulnerabilities, a review of the required patches, and advice on

[Full-disclosure] Evading Oracle Database IDS and Auditing Solutions

2006-12-12 Thread Integrigy Alerts
More and more Oracle Database customers are implementing IDS and auditing solutions to satisfy legislative requirements like SOX and HIPAA. Often these tools are implemented with little testing or awareness that there are potentially multiple techniques that can easily be used to evade these