CVE-2007-3853
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 and 10.2.0.3 allow remote authenticated users to have unknown impact via (1) DBMS_JAVA_TEST in the JavaVM component (DB01), (2) Oracle Text component (DB09), and (3) MDSYS.SDO_GEOR_INT in the Spatial component (DB15). NOTE: a reliable researcher claims that DB01 is SQL injection in DBMS_PRVTAQIS.
Multiples vulnerabilidades no especificadas en Oracle Database 10.1.0.5 y 10.2.0.3 permiten a atacantes remotos autenticados tener un impacto desconocido mediante (1) DBMS_JAVA_TEST en el componente JavaVM component (DB01), (2) Oracle Text component (DB09), y (3) MDSYS.SDO_GEOR_INT en el componente Spatial (DB15).
NOTA: Un investigador fiable indica que DB01 es inyección de SQL en DBMS_PRVTAQIS.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-07-18 CVE Reserved
- 2007-07-18 CVE Published
- 2024-08-07 CVE Updated
- 2024-09-12 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (13)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/26114 | Third Party Advisory | |
http://secunia.com/advisories/26166 | Third Party Advisory | |
http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_July_2007_Analysis.pdf | X_refsource_misc | |
http://www.oracle.com/technetwork/topics/security/cpujul2007-087014.html | X_refsource_confirm | |
http://www.red-database-security.com/advisory/oracle_cpu_jul_2007.html | X_refsource_misc | |
http://www.securityfocus.com/archive/1/474000 | Mailing List | |
http://www.securitytracker.com/id?1018415 | Vdb Entry | |
http://www.us-cert.gov/cas/techalerts/TA07-200A.html | Third Party Advisory | |
http://www.vupen.com/english/advisories/2007/2562 | Vdb Entry | |
http://www.vupen.com/english/advisories/2007/2635 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/35490 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oracle Search vendor "Oracle" | Database Server Search vendor "Oracle" for product "Database Server" | 10.1.0.5 Search vendor "Oracle" for product "Database Server" and version "10.1.0.5" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Database Server Search vendor "Oracle" for product "Database Server" | 10.2.0.3 Search vendor "Oracle" for product "Database Server" and version "10.2.0.3" | - |
Affected
|