First published: Wed Apr 18 2007(Updated: )
Unspecified vulnerability in the Change Data Capture (CDC) component in Oracle Database 9.2.0.7, 10.1.0.5, and 10.2.0.2 has unknown impact and attack vectors, aka DB09. NOTE: as of 20070424, oracle has not disputed reliable claims that this issue involves multiple SQL injection vulnerabilities in the DBMS_CDC_PUBLISH with remote authenticated vectors involving the "java classes in CDC.jar."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Database | =10.2.0.2 | |
Oracle Database | =9.2.0.7 | |
Oracle Database | =10.1.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2115 may involve multiple SQL injection vulnerabilities in the Oracle Database, leading to unknown impacts.
CVE-2007-2115 affects Oracle Database versions 9.2.0.7, 10.1.0.5, and 10.2.0.2.
To mitigate CVE-2007-2115, it is recommended to apply the latest security patches provided by Oracle.
Yes, CVE-2007-2115 is considered a serious security issue due to its nature of potentially allowing SQL injection attacks.
Yes, as of April 2007, Oracle has not disputed reliable claims regarding the vulnerabilities associated with CVE-2007-2115.