Lucene search

K
cveOracleCVE-2009-0992
HistoryApr 15, 2009 - 10:30 a.m.

CVE-2009-0992

2009-04-1510:30:00
oracle
web.nvd.nist.gov
86
cve-2009-0992
oracle database
remote code execution
sql injection
confidentiality
integrity
nvd

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:P/A:N

AI Score

6.3

Confidence

Low

EPSS

0.085

Percentile

94.5%

Unspecified vulnerability in the Advanced Queuing component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect confidentiality and integrity, related to DBMS_AQIN. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on reliable researcher claims that this issue is SQL injection in the DEQ_EXEJOB procedure.

Affected configurations

Nvd
Node
oracledatabase_10gMatch10.1.0.5
OR
oracledatabase_10gMatch10.2.0.4
OR
oracledatabase_11gMatch11.1.0.7
VendorProductVersionCPE
oracledatabase_10g10.1.0.5cpe:2.3:a:oracle:database_10g:10.1.0.5:*:*:*:*:*:*:*
oracledatabase_10g10.2.0.4cpe:2.3:a:oracle:database_10g:10.2.0.4:*:*:*:*:*:*:*
oracledatabase_11g11.1.0.7cpe:2.3:a:oracle:database_11g:11.1.0.7:*:*:*:*:*:*:*

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:P/A:N

AI Score

6.3

Confidence

Low

EPSS

0.085

Percentile

94.5%