HIGH · 10.0

CVE-2008-0347

Unspecified vulnerability in the Oracle Ultra Search component in Oracle Collaboration Suite 10.1.2; Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; and Application Server 9.0.4.3 and 10.1.2.0.2; has unknow...

Vulnerability Description

Unspecified vulnerability in the Oracle Ultra Search component in Oracle Collaboration Suite 10.1.2; Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; and Application Server 9.0.4.3 and 10.1.2.0.2; has unknown impact and local attack vectors, aka OCS01. NOTE: Oracle has not disputed a reliable claim that this issue is related to WKSYS schema privileges.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
OracleApplication Server1.0.2.2
OracleApplication Server 9I9.0.4.3
OracleCollaboration Suite10.1.2
OracleDatabase Server9.0.1.5
OracleE-Business Suite11.5.9
OraclePeoplesoft Enterprise Peopletools8.47

References

FAQ

What is CVE-2008-0347?

CVE-2008-0347 is a vulnerability with a CVSS score of 10.0 (HIGH). Unspecified vulnerability in the Oracle Ultra Search component in Oracle Collaboration Suite 10.1.2; Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; and Application Server 9.0.4.3 and 10.1.2.0.2; has unknow...

How severe is CVE-2008-0347?

CVE-2008-0347 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-0347?

Check the references section above for vendor advisories and patch information. Affected products include: Oracle Application Server, Oracle Application Server 9I, Oracle Collaboration Suite, Oracle Database Server, Oracle E-Business Suite.