PT-2007-3472 · Oracle · Oracle Database Server+4
Published
2007-04-18
·
Updated
2018-10-16
·
CVE-2007-2130
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Oracle Database Server versions 9.2.0.1 through 10.2.0.1
Oracle Application Server versions 9.0.4.3 through 10.1.2.0.2
Oracle Collaboration Suite version 10.1.2
Oracle E-Business Suite (affected versions not specified)
Description
The issue allows remote authenticated attackers to exploit an unspecified vulnerability in the Workflow Cartridge, with unknown impact. Additionally, the current Oracle version has multiple vulnerabilities that enable remote attackers to bypass security restrictions, execute arbitrary SQL commands, and gain access to sensitive data.
Recommendations
For Oracle Database Server versions 9.2.0.1 through 10.2.0.1, update to a version that includes the necessary security patches.
For Oracle Application Server versions 9.0.4.3 through 10.1.2.0.2, apply the recommended security fixes to prevent exploitation.
For Oracle Collaboration Suite version 10.1.2, consider restricting access to sensitive data until a patch is available.
For Oracle E-Business Suite, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Application Server
Oracle Collaboration Suite
Oracle Database
Oracle Database Server
Oracle E-Business Suite