Vulnerability Name: | CVE-2009-0981 (CCN-50027) | ||||||||
Assigned: | 2009-04-14 | ||||||||
Published: | 2009-04-14 | ||||||||
Updated: | 2018-10-10 | ||||||||
Summary: | Unspecified vulnerability in the Application Express component in Oracle Database 11.1.0.7 allows remote authenticated users to affect confidentiality, related to APEX. Note: the previous information was obtained from the April 2009 CPU. Oracle has not commented on reliable researcher claims that this issue allows remote authenticated users to obtain APEX password hashes from the WWV_FLOW_USERS table via a SELECT statement. | ||||||||
CVSS v3 Severity: | 3.5 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N) 3.0 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-0981 Source: OSVDB Type: UNKNOWN 53738 Source: CCN Type: SA34693 Oracle Products Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 34693 Source: CCN Type: SECTRACK ID: 1022052 Oracle Database Bugs Let Remote Authenticated Users Access and Modify Data and Remote Users Cause Denial of Service Conditions Source: CCN Type: Oracle Critical Patch Update Advisory - April 2009 Oracle Critical Patch Update Advisory - April 2009 Source: CONFIRM Type: UNKNOWN http://www.oracle.com/technetwork/topics/security/cpuapr2009-099563.html Source: CCN Type: OSVDB ID: 53738 Oracle Database Application Express (APEX) FLOWS_030000.WWV_FLOW_USER User Password Hash Disclosure Source: CCN Type: Red-Database-Security Advisory 14 April 2009 (V 1.00) Unprivileged DB users can see APEX password hashes in FLOWS_030000.WWV_FLOW_USER [CVE-2009-0981] Source: MISC Type: UNKNOWN http://www.red-database-security.com/advisory/apex_password_hashes.html Source: BUGTRAQ Type: UNKNOWN 20090416 Unprivileged DB users can see APEX password hashes Source: BID Type: UNKNOWN 34461 Source: CCN Type: BID-34461 Oracle April 2009 Critical Patch Update Multiple Vulnerabilities Source: SECTRACK Type: UNKNOWN 1022052 Source: CERT Type: US Government Resource TA09-105A Source: XF Type: UNKNOWN oracle-database-apex-password-hash(50027) Source: EXPLOIT-DB Type: UNKNOWN 8456 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |