First published: Wed Oct 17 2007(Updated: )
Multiple SQL injection vulnerabilities in the CTXSYS Intermedia application for the Oracle Text component (CTX_DOC) in Oracle Database 10.1.0.5 and 10.2.0.3 allow remote authenticated users to execute arbitrary SQL commands via the (1) THEMES, (2) GIST, (3) TOKENS, (4) FILTER, (5) HIGHLIGHT, and (6) MARKUP procedures, aka DB03. NOTE: remote unauthenticated attack vectors exist when CTXSYS is used with oracle Application Server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Database | =10.1.0.5 | |
Oracle Database | =10.2.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5508 is considered a high severity vulnerability due to its potential for remote SQL injection attacks.
To mitigate CVE-2007-5508, upgrade to a patched version of the Oracle Database that addresses this vulnerability.
CVE-2007-5508 affects users running Oracle Database versions 10.1.0.5 and 10.2.0.3.
The impacts of CVE-2007-5508 include the ability for authenticated users to execute arbitrary SQL commands, potentially compromising database integrity.
CVE-2007-5508 specifically affects the CTXSYS Intermedia application for the Oracle Text component, affecting various functions like THEMES, GIST, and TOKENS.