CVE-2007-3854 - CVE House
Back to Database
Status published Medium CVE-2007-3854

Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.5...

Vulnerability Description

Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.5 allow remote authenticated users to have unknown impact via (1) SYS.DBMS_PRVTAQIS in the Advanced Queuing component (DB02) and (2) MDSYS.MD in the Spatial component (DB12). NOTE: Oracle has not disputed reliable researcher claims that DB02 is for SQL injection and DB12 is for a buffer overflow.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-3854

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

apex, application server, collaboration suite, database server, e-business suite, peoplesoft enterprise customer relationship management, peoplesoft enterprise human capital management, peoplesoft enterprise peopletools, secure enterprise search
Vulnerable Versions:
1.5.0, 1.6.1, 2.0, 2.2, 1.0.2.2, 9.0.4.3, 10.1.2.0.1, 10.1.2.0.2, 10.1.2.1.0, 10.1.2.2.0, 10.1.3.0.0, 10.1.3.1.0, 10.1.3.2.0, 10.1.3.3.0, 10.1.2, 9.0.1.5, 9.2.0.7, 9.2.0.8, 9.2.0.8dv, 10.1.0.5, 10.2.0.2, 10.2.0.3, 11.5.8, 11.5.9, 11.5.10, 11.5.10.2, 12.0.0, 12.0.1, 8.9, 9.0, 8.22, 8.47, 8.48, 8.49, 10.1.6, 10.1.8

Timeline

Official Publish: July 18th, 2007
Last Modified: August 7th, 2024
Added to House: July 18th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.