CVE-2008-3976
Unspecified vulnerability in the Oracle Spatial component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than…
Does this matter?
Lower severity and a low EPSS score (1.76%). Track it; it rarely justifies an emergency change on its own.
Description
Unspecified vulnerability in the Oracle Spatial component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2009-3413 and CVE-2009-3414.
- CVSS 2.0
- 5.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
- EPSS
- 1.76% probability · 77th percentile
- CISA KEV
- Not listed
- Affected
- oracle/database 10g · oracle/database 9i
- Source
- secalert_us@oracle.com
References
- http://secunia.com/advisories/32291Permissions Required
- http://www.oracle.com/technetwork/topics/security/cpuoct2008-100299.htmlVendor Advisory
- http://www.securitytracker.com/id?1021050Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2008/2825Not Applicable
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45882
- http://secunia.com/advisories/32291Permissions Required
- http://www.oracle.com/technetwork/topics/security/cpuoct2008-100299.htmlVendor Advisory
- http://www.securitytracker.com/id?1021050Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2008/2825Not Applicable
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45882
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.