Back to search
CVE-2008-1816
Published: Apr 16, 2008
Modified: Aug 7, 2024
PUBLISHED
Description
Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 and 10.2.0.3 have unknown impact and remote authenticated attack vectors related to (1) SDO_UTIL in the Oracle Spatial component, aka DB05; or (2) fine grained auditing in the Audit component, aka DB14. NOTE: the previous information was obtained from the Oracle CPU. Oracle has not commented on reliable researcher claims that DB05 is SQL injection.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
oracle-cpu-april-2008(41858)
vdb-entry
x_refsource_XF
ADV-2008-1267
vdb-entry
x_refsource_VUPEN
ADV-2008-1233
vdb-entry
x_refsource_VUPEN
oracle-database-sdoutil-sql-injection(41999)
vdb-entry
x_refsource_XF
oracle-database-audit-unspecified(42000)
vdb-entry
x_refsource_XF
1019855
vdb-entry
x_refsource_SECTRACK
29829
third-party-advisory
x_refsource_SECUNIA
HPSBMA02133
vendor-advisory
x_refsource_HP
http://www.oracle.com/technetwork/topics/security/cpuapr2008-082075.html
x_refsource_CONFIRM
29874
third-party-advisory
x_refsource_SECUNIA
20080416 Oracle - SQL Injection Vulnerability in SDO_UTIL [DB05]
mailing-list
x_refsource_BUGTRAQ
SSRT061201
vendor-advisory
x_refsource_HP
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now