Risk: Medium
A flaw has been identified in Oracle database 10g, but a patch will not be issued until January.
Athough an attack requires authentication to the database, if this is achieved it may then be possible to remotely execute code.
Oracle will patch this vulnerability in the next quarterly update, due to be released in January 2007.
Companies using this database are urged to monitor traffic for malicious activity and should only allow trusted employers to have access.