PT-2009-4446 · Oracle · Oracle Database
Published
2009-10-22
·
Updated
2012-10-23
·
CVE-2009-1991
CVSS v2.0
3.6
Low
| Vector | AV:N/AC:H/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Oracle Database versions 9.2.0.8 through 10.2.0.4
Description:
The issue affects confidentiality and integrity, and is related to
CTXSYS.DRVXTABC. It may be related to SQL injection vulnerabilities via the idx owner or idx name parameters to the create tables procedure.Recommendations:
For Oracle Database versions 9.2.0.8 through 10.2.0.4, consider restricting access to the
create tables procedure to minimize the risk of exploitation, and avoid using the idx owner and idx name parameters until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Database