Vulnerability Name: | CVE-2009-1991 (CCN-53849) | ||||||||
Assigned: | 2009-10-21 | ||||||||
Published: | 2009-10-21 | ||||||||
Updated: | 2012-10-23 | ||||||||
Summary: | Unspecified vulnerability in the Oracle Text component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity, related to CTXSYS.DRVXTABC. Note: the previous information was obtained from the October 2009 CPU. Oracle has not commented on claims from an established researcher that this is for multiple SQL injection vulnerabilities via the (1) idx_owner or (2) idx_name parameters to the create_tables procedure. | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 3.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:S/C:P/I:P/A:N) 2.6 Low (Temporal CVSS v2 Vector: AV:N/AC:H/Au:S/C:P/I:P/A:N/E:U/RL:OF/RC:C)
2.6 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:S/C:P/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Other | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-1991 Source: OSVDB Type: UNKNOWN 59113 Source: CCN Type: SA37027 Oracle Database Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 37027 Source: CCN Type: SECTRACK ID: 1023057 Oracle Database Flaws Let Remote Users Take Fully Control of the Database or System Source: CCN Type: Oracle Critical Patch Update Advisory - October 2009 Oracle Critical Patch Update Advisory - October 2009 Source: CONFIRM Type: UNKNOWN http://www.oracle.com/technetwork/topics/security/cpuoct2009-096303.html Source: CCN Type: OSVDB ID: 59113 Oracle Database Text ctxsys.drvxtabc.create_tables Multiple Parameter SQL Injection Source: BID Type: UNKNOWN 36748 Source: CCN Type: BID-36748 Oracle Database Text Component 'ctxsys.drvxtabc.create_tables' Remote SQL Injection Vulnerability Source: SECTRACK Type: UNKNOWN 1023057 Source: CERT Type: US Government Resource TA09-294A Source: XF Type: UNKNOWN oracle-db-text-unspecified(53849) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |