This host is running Oracle database and is prone to buffer overflow and denial of service vulnerabilities.
Successful exploitation allows an attacker to execute arbitrary code. It can also be exploited to cause denial of service by killing Oracle server process. Impact Level: Application
Apply patches from below link, http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html
The flaws are due to error in 'MDSYS.MD' package that is used in the Oracle spatial component. The package has EXECUTE permission to PUBLIC, so any Oracle database user can exploit the vulnerability to execute arbitrary code.
Oracle Database server versions 184.108.40.206, 220.127.116.11, 18.104.22.168, and 10.1.0.4
Updated on 2015-03-25
- SAP MaxDB 'serv.exe' Unspecified Remote Code Execution Vulnerability
- MySQL 5.5.20 Unspecified Remote Code Execution Vulnerability
- Oracle Database Server Multiple Unspecified Vulnerabilities
- IBM DB2 Multiple Unspecified Vulnerabilities (Linux)
- IBM DB2 Audit Facility Local Privilege Escalation Vulnerability (Linux)