CVE-2008-3973: Low severity oracle database vulnerability
Published Jan 14, 2009
·Updated
Unspecified vulnerability in the SQLPlus Windows GUI component in Oracle Database allows local users to affect confidentiality via unknown vectors.
Affected Software
7 affected components
Oracle Database 10g=10.1.0.5
Oracle Database 10g=10.1.2.3
Oracle Database 10g=10.1.4.2
Oracle Database 10g=10.2.0.2
Oracle Database 10g=10.2.0.3
Oracle Database 10g=10.2.0.4
Oracle Database 11g
Event History
Jan 14, 2009
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-3973?
CVE-2008-3973 is considered a moderate severity vulnerability due to its potential impact on data confidentiality.
2
How do I fix CVE-2008-3973?
To mitigate CVE-2008-3973, users should apply the latest patches provided by Oracle for the affected database versions.
3
Which versions of Oracle Database are affected by CVE-2008-3973?
CVE-2008-3973 affects several versions of Oracle Database 10g and 11g, including specific versions like 10.1.0.5 and 10.2.0.4.
4
Can local users exploit CVE-2008-3973?
Yes, local users can exploit CVE-2008-3973 to potentially affect confidentiality in the impacted SQL*Plus Windows GUI component.
5
Is there any workaround for CVE-2008-3973?
Currently, there are no documented workarounds for CVE-2008-3973 other than applying available security updates.