CVE-2006-0435 describes an unspecified vulnerability in Oracle PL/SQL, affecting various versions of Oracle Database Server, Application Server, E-Business Suite, and Collaboration Suite. This flaw allows attackers to bypass the PLSQLExclusion list, gaining unauthorized access to otherwise restricted packages and procedures. With a CVSS score of 7.5, this vulnerability is considered highly severe due to its network-based attack vector, low access complexity, and potential for partial compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been identified, and community discussion is minimal, the FAUCET Risk Score of 65/100 indicates a notable risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:oracle:application_server:*:*:*:*:*:*:*:* | ||
1.0.2CPE matchmatch criteria | cpe:2.3:a:oracle:application_server:1.0.2:*:*:*:*:*:*:* | ||
1.0.2.0CPE matchmatch criteria | cpe:2.3:a:oracle:application_server:1.0.2.0:*:*:*:*:*:*:* | ||
1.0.2.1CPE matchmatch criteria | cpe:2.3:a:oracle:application_server:1.0.2.1:*:*:*:*:*:*:* | ||
1.0.2.1sCPE matchmatch criteria | cpe:2.3:a:oracle:application_server:1.0.2.1s:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.