PT-2007-6529 · Oracle · Oracle Database

Publicado

2007-10-17

·

Atualizado

2012-10-23

·

CVE-2007-5505

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Oracle Database versions 9.0.1.5 and later Oracle Database version 9.2.0.8 Oracle Database version 9.2.0.8DV Oracle Database version 10.1.0.5 Oracle Database version 10.2.0.3
Description: The issue is related to multiple unspecified vulnerabilities in various components, including the Export component, Oracle Text, Spatial component, and Advanced Security Option. These vulnerabilities have unknown impact and remote attack vectors, allowing remote attackers to bypass security restrictions, execute arbitrary SQL commands, and gain access to sensitive data.
Recommendations: For Oracle Database version 9.0.1.5 and later, update to a version that addresses these vulnerabilities. For Oracle Database version 9.2.0.8, consider disabling the Export component and restricting access to Oracle Text until a patch is available. For Oracle Database version 9.2.0.8DV, restrict access to the Spatial component to minimize the risk of exploitation. For Oracle Database version 10.1.0.5, avoid using the Advanced Security Option until the issue is resolved. For Oracle Database version 10.2.0.3, consider temporarily disabling the Oracle Text component until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-5505

Produtos afetados

Oracle Database