First published: Wed Oct 17 2007(Updated: )
The XML DB (XMLDB) component in Oracle Database 9.2.0.8, 9.2.0.8DV, and 10.1.0.5 generates incorrect audit entries in the USERID column in which (1) long usernames are trimmed to 5 characters, or (2) short entries contain any extra characters from usernames in previous entries, aka DB23.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Database | =9.2.0.8 | |
Oracle Database | =9.2.0.8dv | |
Oracle Database | =10.1.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5513 is considered a high-severity vulnerability due to its potential impact on system audit integrity.
To fix CVE-2007-5513, it is recommended to upgrade to a patched version of Oracle Database where this issue has been addressed.
CVE-2007-5513 affects Oracle Database versions 9.2.0.8, 9.2.0.8DV, and 10.1.0.5.
CVE-2007-5513 causes data integrity issues by generating incorrect audit entries, which may misrepresent user activity.
While not classified as critical, CVE-2007-5513 poses significant risks due to its effects on auditing and user identification.