Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5, 9.2.0.7, and 10.1.0.5...
Vulnerability Description
Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5, 9.2.0.7, and 10.1.0.5 have unknown impact and attack vectors related to (1) the Advanced Queuing component and sys.dbms_aqsys.dbms_aq privileges (DB01), (2) Advanced Replication and sys.dbms_repcat_untrusted (DB07), and (3) Oracle Text and ctxload (DB15). NOTE: Oracle has not publicly claims by reliable researchers that DB01 is for SQL injection in the SYS.DBMS_AQ_INV package, and DB07 is for a buffer overflow in the UNREGISTER_SNAPSHOT procedure in the DBMS_REPCAT_UNTRUSTED package.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-0268
Credits & Attribution
No credits recorded in the NVD database.
References
- http://osvdb.org/32913
- http://www.securityfocus.com/archive/1/458475/100/100/threaded
- http://secunia.com/advisories/23794
- http://osvdb.org/32921
- http://www.securityfocus.com/bid/22083
- http://www.kb.cert.org/vuls/id/221788
- http://osvdb.org/32907
- http://www.securityfocus.com/archive/1/458005/100/0/threaded
- http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html
- http://www.us-cert.gov/cas/techalerts/TA07-017A.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31541
- http://www.red-database-security.com/advisory/oracle_sql_injection_dbms_aq_inv.html
- http://securitytracker.com/id?1017522
More from oracle
View All →Affected Vendor
oracle
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.