Lucene search

K
cve[email protected]CVE-2008-2592
HistoryJul 15, 2008 - 11:41 p.m.

CVE-2008-2592

2008-07-1523:41:00
web.nvd.nist.gov
72
cve-2008-2592
unspecified vulnerability
oracle database
advanced replication
fips+
sql injection

5.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:P/A:N

6.1 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

53.2%

Unspecified vulnerability in the Advanced Replication component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.6 has unknown impact and remote authenticated attack vectors related to SYS.DBMS_DEFER_SYS. NOTE: the previous information was obtained from the Oracle July 2008 CPU. Oracle has not commented on reliable researcher claims that this is a SQL injection vulnerability in the DELETE_TRAN procedure.

Affected configurations

NVD
Node
oracleadvanced_replication_component
OR
oracledatabase_serverMatch9.2.0.8
OR
oracledatabase_serverMatch10.1.0.5
OR
oracleoracle_databaseMatch9.0.1.5fips\+
OR
oracleoracle_databaseMatch9.2.0.8dv
OR
oracleoracle_databaseMatch10.2.0.4
OR
oracleoracle_databaseMatch11.1.0.6

5.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:P/A:N

6.1 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

53.2%