scuba漏洞扫描机制

[复制链接]
查看11 | 回复0 | 2013-9-22 11:31:00 | 显示全部楼层 |阅读模式
--scuba中某一漏洞的判断行为

critical
15
Checks if the Oracle Critical Patch Update from April 2009 is applied to the database server. If not, checks if the server is vulnerable to CVE-2009-0986 by searching for it in the list of affected versions published by Oracle.

Known Attacks
Oracle
Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 and 11.1.0.6 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.Install latest security patch update.OraCPU1Oracle CPU1 (Patch Level)OraCPU2OraCPU 2 (Patch Level)OraCPU3OraCPU 3 (Patach Level)OraCPU4OraCPU 4 (Patch Level)OraCPU5OraCPU 5 (Patch Level)OraCPU6OraCPU 6 (Patch Level)OraPatchLevel-deprecatedOracle Patch Level (Windows)OraPatchLevel-deprecatedOracle Patch Level (Unix)OraVerOracle version
#############################
一直想不明白为什么还要加这句判断(!OraCPU1! + !OraCPU2! + !OraCPU3!+ !OraCPU4! + !OraCPU5! + !OraCPU6!) < 200904,
其中OraCPU1与OraCPU2到底想说明什么。
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

主题

0

回帖

4882万

积分

论坛元老

Rank: 8Rank: 8

积分
48824836
热门排行