PT-2007-6529 · Oracle · Oracle Database

Published

2007-10-17

·

Updated

2012-10-23

·

CVE-2007-5505

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Oracle Database versions 9.0.1.5 and later Oracle Database version 9.2.0.8 Oracle Database version 9.2.0.8DV Oracle Database version 10.1.0.5 Oracle Database version 10.2.0.3
Description: The issue is related to multiple unspecified vulnerabilities in various components, including the Export component, Oracle Text, Spatial component, and Advanced Security Option. These vulnerabilities have unknown impact and remote attack vectors, allowing remote attackers to bypass security restrictions, execute arbitrary SQL commands, and gain access to sensitive data.
Recommendations: For Oracle Database version 9.0.1.5 and later, update to a version that addresses these vulnerabilities. For Oracle Database version 9.2.0.8, consider disabling the Export component and restricting access to Oracle Text until a patch is available. For Oracle Database version 9.2.0.8DV, restrict access to the Spatial component to minimize the risk of exploitation. For Oracle Database version 10.1.0.5, avoid using the Advanced Security Option until the issue is resolved. For Oracle Database version 10.2.0.3, consider temporarily disabling the Oracle Text component until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-5505

Affected Products

Oracle Database