PT-2008-1980 · Oracle · Oracle Application Server+3

Published

2008-01-17

·

Updated

2018-10-15

·

CVE-2008-0347

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Oracle Collaboration Suite version 10.1.2 Oracle Database versions 9.2.0.8, 10.1.0.5, and 10.2.0.3 Oracle Application Server versions 9.0.4.3 and 10.1.2.0.2
Description The issue concerns an unspecified vulnerability in the Oracle Ultra Search component, with unknown impact and local attack vectors. It is reportedly related to WKSYS schema privileges.
Recommendations For Oracle Collaboration Suite version 10.1.2, update to a version that addresses the issue related to WKSYS schema privileges. For Oracle Database versions 9.2.0.8, 10.1.0.5, and 10.2.0.3, restrict access to the WKSYS schema to minimize potential impact. For Oracle Application Server versions 9.0.4.3 and 10.1.2.0.2, consider limiting privileges related to the Ultra Search component until a fix is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2008-0347

Affected Products

Oracle Application Server
Oracle Collaboration Suite
Oracle Database
Oracle Ultra Search