PT-2007-6529 · Oracle · Oracle Database
Published
2007-10-17
·
Updated
2012-10-23
·
CVE-2007-5505
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Oracle Database versions 9.0.1.5 and later
Oracle Database version 9.2.0.8
Oracle Database version 9.2.0.8DV
Oracle Database version 10.1.0.5
Oracle Database version 10.2.0.3
Description:
The issue is related to multiple unspecified vulnerabilities in various components, including the Export component, Oracle Text, Spatial component, and Advanced Security Option. These vulnerabilities have unknown impact and remote attack vectors, allowing remote attackers to bypass security restrictions, execute arbitrary SQL commands, and gain access to sensitive data.
Recommendations:
For Oracle Database version 9.0.1.5 and later, update to a version that addresses these vulnerabilities.
For Oracle Database version 9.2.0.8, consider disabling the Export component and restricting access to Oracle Text until a patch is available.
For Oracle Database version 9.2.0.8DV, restrict access to the Spatial component to minimize the risk of exploitation.
For Oracle Database version 10.1.0.5, avoid using the Advanced Security Option until the issue is resolved.
For Oracle Database version 10.2.0.3, consider temporarily disabling the Oracle Text component until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Database