<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet type="text/xsl" href="http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/1687073.xsl"?>
<?xml-stylesheet type="text/css" href="http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/1686935.css"?>
<cvrf:cvrfdoc xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1">
   <DocumentTitle xml:lang="en">Oracle Security Alert for CVE-2012-3132 - BETA ORACLE CVRF</DocumentTitle>
   <DocumentType xml:lang="en">Oracle Security Alert</DocumentType>
   <DocumentPublisher Type="Vendor"/>
   <DocumentTracking>
      <Identification>
         <ID>CVE-2012-3132</ID>
      </Identification>
      <Status>Final</Status>
      <Version>1.0</Version>
      <RevisionHistory>
         <Revision>
            <Number>1.0</Number>
            <Date>2012-08-10T13:00:00-07:00</Date>
            <Description>Initial Distribution</Description>
         </Revision>
      </RevisionHistory>
      <InitialReleaseDate>2012-08-10T13:00:00-07:00</InitialReleaseDate>
      <CurrentReleaseDate>2012-08-10T13:00:00-07:00</CurrentReleaseDate>
   </DocumentTracking>
   <DocumentNotes>
      <Note Type="Summary" Ordinal="1" Title="Summary" Audience="All" xml:lang="en">This document contains descriptions of Oracle product security vulnerabilities which have had fixes released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including fix distribution information can be found at the Oracle sites referenced in this document.</Note>
   </DocumentNotes>
   <DocumentDistribution>This document is published at: http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/1721030.xml</DocumentDistribution>
   <DocumentReferences>
      <Reference Type="External">
         <URL>http://www.oracle.com/technetwork/topics/security/alert-cve-2012-3132-1721017.html</URL>
         <Description>URL to html version of Advisory</Description>
      </Reference>
   </DocumentReferences>
   <Acknowledgments/>
   <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
      <Branch Type="Vendor" Name="Oracle">
         <Branch Type="Product Family" Name="Oracle Database Server">
            <Branch Type="Product Name" Name="Oracle Database">
               <Branch Type="Product Version" Name="10.2.0.3">
                  <FullProductName ProductID="P-5V-10.2.0.3">Oracle Database Version 10.2.0.3</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="10.2.0.4">
                  <FullProductName ProductID="P-5V-10.2.0.4">Oracle Database Version 10.2.0.4</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="10.2.0.5">
                  <FullProductName ProductID="P-5V-10.2.0.5">Oracle Database Version 10.2.0.5</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.1.0.7">
                  <FullProductName ProductID="P-5V-11.1.0.7">Oracle Database Version 11.1.0.7</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.2.0.2">
                  <FullProductName ProductID="P-5V-11.2.0.2">Oracle Database Version 11.2.0.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.2.0.3">
                  <FullProductName ProductID="P-5V-11.2.0.3">Oracle Database Version 11.2.0.3</FullProductName>
               </Branch>
            </Branch>
         </Branch>
      </Branch>
   </ProductTree>
   <Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3132</Title>
      <Notes>
         <Note Type="Details" Ordinal="1" Title="Details" Audience="All">Vulnerability in the Core RDBMS component of Oracle Database Server.  This vulnerability requires Create session, create table privileges for a successful attack.  Supported versions that are affected are 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2 and  11.2.0.3. Easily exploitable vulnerability allows successful authenticated network attacks via Oracle NET.  Successful attack of this vulnerability can result in unauthorized takeover of Core RDBMS possibly including arbitrary code execution within the Core RDBMS.   Note: 11.2.0.2 and 11.2.0.3 do not require patching if the July 2012 Critical Patch Update has been applied. CVSS Base Score 6.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:P+/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3132</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-10.2.0.3</ProductID>
            <ProductID>P-5V-10.2.0.4</ProductID>
            <ProductID>P-5V-10.2.0.5</ProductID>
            <ProductID>P-5V-11.1.0.7</ProductID>
            <ProductID>P-5V-11.2.0.2</ProductID>
            <ProductID>P-5V-11.2.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.5</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CVE-2012-3132</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/alert-cve-2012-3132-1721017.html</URL>
            <ProductID>P-5V-10.2.0.3</ProductID>
            <ProductID>P-5V-10.2.0.4</ProductID>
            <ProductID>P-5V-10.2.0.5</ProductID>
            <ProductID>P-5V-11.1.0.7</ProductID>
            <ProductID>P-5V-11.2.0.2</ProductID>
            <ProductID>P-5V-11.2.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
</cvrf:cvrfdoc>
