CVE-2007-2111

Description

SQL injection vulnerability in the SYS.DBMS_AQADM_SYS package in Oracle Database 9.0.1.5, 9.2.0.7, and 10.1.0.5 allows remote authenticated users to inject arbitrary SQL commands via unknown vectors, aka DB04. NOTE: as of 20070424, Oracle has not disputed reliable claims that DB04 is actually for multiple vulnerabilities.

Risk Information

Base Score
8.8
MODERATE
Vector
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
2.413

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Oracle 10.1.0.5Windows
Multiple Vulnerabilities are affected in Oracle 9.0.1.5Windows
Multiple Vulnerabilities are affected in Oracle Database Server 9.0.1.5Windows
Multiple Vulnerabilities are affected in Oracle Database Server 9.2.0.7Windows
Multiple Vulnerabilities are affected in Oracle Database Server 10.1.0.5Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234