First published: Wed Jul 18 2007(Updated: )
Unspecified vulnerability in the Oracle Data Mining component for Oracle Database 10g Release 2 10.2.0.2 and 10.2.0.3, 10g 10.1.0.5, and Oracle9i Database Release 2 9.2.0.7, 9.2.0.8, and 9.2.0.8DV has unknown impact and remote authenticated attack vectors related to DMSYS.DMP_SYS, aka DB04.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Database | =9.2.0.7 | |
Oracle Database | =9.2.0.8 | |
Oracle Database | =9.2.0.8dv | |
Oracle Database | =10.2.0.2 | |
Oracle Database | =10.2.0.3 | |
Oracle Database 10g | =standard_10.1.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2007-3856 has not been explicitly defined, but it involves unspecified vulnerabilities that could allow remote authenticated attacks.
To fix CVE-2007-3856, upgrade to a patched version of the Oracle Database identified in the vendor's release notes.
CVE-2007-3856 affects Oracle Database versions 9.2.0.7, 9.2.0.8, 10.2.0.2, 10.2.0.3, and the Standard Edition 10.1.0.5.
Yes, CVE-2007-3856 can be exploited by remote authenticated attackers.
No specific workarounds are provided for CVE-2007-3856, so upgrading to a secure version is recommended.