CVE-2008-1815
Unspecified vulnerability in the Change Data Capture component in Oracle Database 10.1.0.5, 10.2.0.3, and 11.1.0.6 has unknown impact and remote authenticated attack vectors related to DBMS_CDC_UTILITY, aka DB02.
Does this matter?
Lower severity and a low EPSS score (1.26%). Track it; it rarely justifies an emergency change on its own.
Description
Unspecified vulnerability in the Change Data Capture component in Oracle Database 10.1.0.5, 10.2.0.3, and 11.1.0.6 has unknown impact and remote authenticated attack vectors related to DBMS_CDC_UTILITY, aka DB02. NOTE: the previous information was obtained from the April 2008 CPU. Oracle has not commented on reliable researcher claims that DB02 is for SQL injection in LOCK_CHANGE_SET.
- CVSS 2.0
- 5.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
- EPSS
- 1.26% probability · 68th percentile
- CISA KEV
- Not listed
- Affected
- oracle/database 10g · oracle/database 11g
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/29829Vendor Advisory
- http://secunia.com/advisories/29874Vendor Advisory
- http://www.oracle.com/technetwork/topics/security/cpuapr2008-082075.html
- http://www.securityfocus.com/archive/1/491024/100/0/threaded
- http://www.securityfocus.com/archive/1/491522/30/390/threaded
- http://www.securitytracker.com/id?1019855
- http://www.vupen.com/english/advisories/2008/1233/referencesVendor Advisory
- http://www.vupen.com/english/advisories/2008/1267/referencesVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41858
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41998
- http://secunia.com/advisories/29829Vendor Advisory
- http://secunia.com/advisories/29874Vendor Advisory
- http://www.oracle.com/technetwork/topics/security/cpuapr2008-082075.html
- http://www.securityfocus.com/archive/1/491024/100/0/threaded
- http://www.securityfocus.com/archive/1/491522/30/390/threaded
- http://www.securitytracker.com/id?1019855
- http://www.vupen.com/english/advisories/2008/1233/referencesVendor Advisory
- http://www.vupen.com/english/advisories/2008/1267/referencesVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41858
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41998
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.