CVE Database
/

CVE-2009-1991

Back to search

CVE-2009-1991

Published: Oct 22, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

Unspecified vulnerability in the Oracle Text component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity, related to CTXSYS.DRVXTABC. NOTE: the previous information was obtained from the October 2009 CPU. Oracle has not commented on claims from an established researcher that this is for multiple SQL injection vulnerabilities via the (1) idx_owner or (2) idx_name parameters to the create_tables procedure.

VendorProductVersions

n/a

n/a

affected
n/a

References

36748
vdb-entry
x_refsource_BID
37027
third-party-advisory
x_refsource_SECUNIA
1023057
vdb-entry
x_refsource_SECTRACK
TA09-294A
third-party-advisory
x_refsource_CERT
59113
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now