CVE-2007-0271
Unspecified vulnerability in Oracle Database 9.0.1.5 and 9.2.0.7 has unknown impact and attack vectors related to the Log Miner component and sys.dbms_log_mnr privileges, aka DB04.
Does this matter?
Lower severity and a low EPSS score (4.22%). Track it; it rarely justifies an emergency change on its own.
Description
Unspecified vulnerability in Oracle Database 9.0.1.5 and 9.2.0.7 has unknown impact and attack vectors related to the Log Miner component and sys.dbms_log_mnr privileges, aka DB04. NOTE: Oracle has not disputed a reliable researcher claim that this is a buffer overflow in the ADD_LOGFILE procedure for the SYS.DBMS_LOGMNR package that allows code execution.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 4.22% probability · 90th percentile
- CISA KEV
- Not listed
- Affected
- oracle/database server
- Source
- cve@mitre.org
References
- http://osvdb.org/32910
- http://secunia.com/advisories/23794Patch, Vendor Advisory
- http://securitytracker.com/id?1017522
- http://www.appsecinc.com/resources/alerts/oracle/2007-01.shtml
- http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html
- http://www.securityfocus.com/archive/1/458006/100/0/threaded
- http://www.securityfocus.com/archive/1/458475/100/100/threaded
- http://www.securityfocus.com/bid/22083
- http://www.us-cert.gov/cas/techalerts/TA07-017A.htmlPatch, US Government Resource
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31541
- http://osvdb.org/32910
- http://secunia.com/advisories/23794Patch, Vendor Advisory
- http://securitytracker.com/id?1017522
- http://www.appsecinc.com/resources/alerts/oracle/2007-01.shtml
- http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html
- http://www.securityfocus.com/archive/1/458006/100/0/threaded
- http://www.securityfocus.com/archive/1/458475/100/100/threaded
- http://www.securityfocus.com/bid/22083
- http://www.us-cert.gov/cas/techalerts/TA07-017A.htmlPatch, US Government Resource
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31541
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.