Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2007-3853
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-3853

Description:
Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 and 10.2.0.3 allow remote authenticated users to have unknown impact via (1) DBMS_JAVA_TEST in the JavaVM component (DB01), (2) Oracle Text component (DB09), and (3) MDSYS.SDO_GEOR_INT in the Spatial component (DB15). NOTE: a reliable researcher claims that DB01 is SQL injection in DBMS_PRVTAQIS.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/35490

ST
  1018415

SAID
  Secunia Advisory: SA26114
  Secunia Advisory: SA26166

MISC
  http://www.red-database-security.com/advisory/oracle_sql_injection_dbms_prvtaqis.html
  http://www.red-database-security.com/advisory/oracle_cpu_jul_2007.html
  http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_July_2007_Analysis.pdf

HP
  http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c00727143

CONFIRM
  http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2007.html

CERT
  http://www.us-cert.gov/cas/techalerts/TA07-200A.html

BUGTRAQ
  http://www.securityfocus.com/archive/1/474000


Return to the previous page.