CVE-2008-2592: SQL Injection
Unspecified vulnerability in the Advanced Replication component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.6 has unknown impact and remote authenticated attack vectors related to SYS.DBMSDEFERSYS. NOTE: the previous information was obtained from the Oracle July 2008 CPU. Oracle has not commented on reliable researcher claims that this is a SQL injection vulnerability in the DELETETRAN procedure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2592?
CVE-2008-2592 has an unspecified severity level and could allow remote authenticated attacks due to unknown impacts.
Which versions of Oracle Database are affected by CVE-2008-2592?
CVE-2008-2592 affects Oracle Database versions 9.0.1.5 FIPS+, 9.2.0.8, 10.1.0.5, 10.2.0.4, and 11.1.0.6.
How do I fix CVE-2008-2592?
To address CVE-2008-2592, it is recommended to apply the latest security patches provided by Oracle for the affected database versions.
What components are impacted by CVE-2008-2592?
CVE-2008-2592 impacts the Advanced Replication component in Oracle Database.
Can CVE-2008-2592 be exploited remotely?
Yes, CVE-2008-2592 can be exploited remotely by authenticated attackers.