MEDIUM · 5.5

CVE-2007-3854

Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.5 allow remote authenticated users to have unknown impact via (1) SYS.DBMS_PRVTAQIS in the Advanced Queuing compon...

Vulnerability Description

Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.5 allow remote authenticated users to have unknown impact via (1) SYS.DBMS_PRVTAQIS in the Advanced Queuing component (DB02) and (2) MDSYS.MD in the Spatial component (DB12). NOTE: Oracle has not disputed reliable researcher claims that DB02 is for SQL injection and DB12 is for a buffer overflow.

CVSS Score

5.5

MEDIUM

AV:N/AC:L/Au:S/C:P/I:P/A:N
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
OracleApex1.5.0
OracleApplication Server1.0.2.2
OracleCollaboration Suite10.1.2
OracleDatabase Server9.0.1.5
OracleE-Business Suite11.5.8
OraclePeoplesoft Enterprise Customer Relationship Management8.9
OraclePeoplesoft Enterprise Human Capital Management8.9
OraclePeoplesoft Enterprise Peopletools8.22
OracleSecure Enterprise Search10.1.6

References

FAQ

What is CVE-2007-3854?

CVE-2007-3854 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.5 allow remote authenticated users to have unknown impact via (1) SYS.DBMS_PRVTAQIS in the Advanced Queuing compon...

How severe is CVE-2007-3854?

CVE-2007-3854 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-3854?

Check the references section above for vendor advisories and patch information. Affected products include: Oracle Apex, Oracle Application Server, Oracle Collaboration Suite, Oracle Database Server, Oracle E-Business Suite.