CVE Database
/

CVE-2007-2108

Back to search

CVE-2007-2108

Published: Apr 18, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.2 on Windows allows remote attackers to have an unknown impact, aka DB01. NOTE: as of 20070424, Oracle has not disputed reliable claims that this issue occurs because the NTLM SSPI AcceptSecurityContext function grants privileges based on the username provided even though all users are authenticated as Guest, which allows remote attackers to gain privileges.

VendorProductVersions

n/a

n/a

affected
n/a

References

TA07-108A
third-party-advisory
x_refsource_CERT
VU#809457
third-party-advisory
x_refsource_CERT-VN
23532
vdb-entry
x_refsource_BID
1017927
vdb-entry
x_refsource_SECTRACK
SSRT061201
vendor-advisory
x_refsource_HP
HPSBMA02133
vendor-advisory
x_refsource_HP
ADV-2007-1426
vdb-entry
x_refsource_VUPEN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now