Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2009-1991
StatusUNKNOWN
DescriptionUnspecified vulnerability in the Oracle Text component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity, related to CTXSYS.DRVXTABC.  NOTE: the previous information was obtained from the October 2009 CPU.  Oracle has not commented on claims from an established researcher that this is for multiple SQL injection vulnerabilities via the (1) idx_owner or (2) idx_name parameters to the create_tables procedure.
SeverityLow
CVSS score3,6
CVSS vector(AV:N/AC:H/Au:S/C:P/I:P/A:N)
PhaseASSIGNED (31.10.2009)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1991
ReferencesBID : 36748
 CERT : TA09-294A
 CONFIRM : http://www.oracle.com/technology/deploy/security/c...
 OSVDB : 59113
 SECTRACK : 1023057
 SECUNIA : 37027
SecurityVulns:Oracle multiple security vulnerabilities

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server