This vulnerability was initially thought to have been fixed as part of the Oracle April 2006 Security Update (BID 17590), but this issue reportedly wasn't patched.

This story continues at http://www.databasejournal.com/news/article.php/3602636