CVE Vulnerabilities

CVE-2007-3854

Published: Jul 18, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.5 allow remote authenticated users to have unknown impact via (1) SYS.DBMS_PRVTAQIS in the Advanced Queuing component (DB02) and (2) MDSYS.MD in the Spatial component (DB12). NOTE: Oracle has not disputed reliable researcher claims that DB02 is for SQL injection and DB12 is for a buffer overflow.

Affected Software

NameVendorStart VersionEnd Version
ApexOracle1.5.0 (including)1.5.0 (including)
ApexOracle1.6.1 (including)1.6.1 (including)
ApexOracle2.0 (including)2.0 (including)
ApexOracle2.2 (including)2.2 (including)
Application_serverOracle1.0.2.2-r2 (including)1.0.2.2-r2 (including)
Application_serverOracle9.0.4.3 (including)9.0.4.3 (including)
Application_serverOracle10.1.2.0.1 (including)10.1.2.0.1 (including)
Application_serverOracle10.1.2.0.2 (including)10.1.2.0.2 (including)
Application_serverOracle10.1.2.1.0 (including)10.1.2.1.0 (including)
Application_serverOracle10.1.2.2.0 (including)10.1.2.2.0 (including)
Application_serverOracle10.1.3.0.0 (including)10.1.3.0.0 (including)
Application_serverOracle10.1.3.1.0 (including)10.1.3.1.0 (including)
Application_serverOracle10.1.3.2.0 (including)10.1.3.2.0 (including)
Application_serverOracle10.1.3.3.0 (including)10.1.3.3.0 (including)
Collaboration_suiteOracle10.1.2 (including)10.1.2 (including)
Database_serverOracle9.0.1.5 (including)9.0.1.5 (including)
Database_serverOracle9.2.0.7-r2 (including)9.2.0.7-r2 (including)
Database_serverOracle9.2.0.8-r2 (including)9.2.0.8-r2 (including)
Database_serverOracle9.2.0.8dv-r2 (including)9.2.0.8dv-r2 (including)
Database_serverOracle10.1.0.5 (including)10.1.0.5 (including)
Database_serverOracle10.2.0.2-r2 (including)10.2.0.2-r2 (including)
Database_serverOracle10.2.0.3-r2 (including)10.2.0.3-r2 (including)
E-business_suiteOracle11.5.8 (including)11.5.8 (including)
E-business_suiteOracle11.5.9 (including)11.5.9 (including)
E-business_suiteOracle11.5.10 (including)11.5.10 (including)
E-business_suiteOracle11.5.10.2 (including)11.5.10.2 (including)
E-business_suiteOracle12.0.0 (including)12.0.0 (including)
E-business_suiteOracle12.0.1 (including)12.0.1 (including)
Peoplesoft_enterprise_customer_relationship_managementOracle8.9 (including)8.9 (including)
Peoplesoft_enterprise_customer_relationship_managementOracle9.0 (including)9.0 (including)
Peoplesoft_enterprise_human_capital_managementOracle8.9 (including)8.9 (including)
Peoplesoft_enterprise_human_capital_managementOracle9.0 (including)9.0 (including)
Peoplesoft_enterprise_peopletoolsOracle8.22 (including)8.22 (including)
Peoplesoft_enterprise_peopletoolsOracle8.47 (including)8.47 (including)
Peoplesoft_enterprise_peopletoolsOracle8.48 (including)8.48 (including)
Peoplesoft_enterprise_peopletoolsOracle8.49 (including)8.49 (including)
Secure_enterprise_searchOracle10.1.6 (including)10.1.6 (including)
Secure_enterprise_searchOracle10.1.8 (including)10.1.8 (including)

References