CVE Database
/

CVE-2008-1813

Back to search

CVE-2008-1813

Published: Apr 16, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 have unknown impact and remote unauthenticated or authenticated attack vectors related to (1) SYS.DBMS_AQ in the Advanced Queuing component, aka DB01; (2) Core RDBMS, aka DB03; (3) SDO_GEOM in Oracle Spatial, aka DB06; (4) Export, aka DB12; and (5) DBMS_STATS in Query Optimizer, aka DB13. NOTE: the previous information was obtained from the Oracle CPU. Oracle has not commented on reliable researcher claims that DB06 is SQL injection, and DB13 occurs when the OUTLN account is reset to use a hard-coded password.

VendorProductVersions

n/a

n/a

affected
n/a

References

oracle-cpu-april-2008(41858)
vdb-entry
x_refsource_XF
ADV-2008-1267
vdb-entry
x_refsource_VUPEN
ADV-2008-1233
vdb-entry
x_refsource_VUPEN
1019855
vdb-entry
x_refsource_SECTRACK
29829
third-party-advisory
x_refsource_SECUNIA
HPSBMA02133
vendor-advisory
x_refsource_HP
29874
third-party-advisory
x_refsource_SECUNIA
SSRT061201
vendor-advisory
x_refsource_HP

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now