CVE-2009-0977: SQL Injection
Unspecified vulnerability in the Advanced Queuing component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity, related to DBMSAQIN. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on reliable researcher claims that this issue is SQL injection in the GRANTTYPEACCESS procedure in the DBMSAQADMSYS package.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0977?
CVE-2009-0977 is considered a high-severity vulnerability affecting Oracle Database versions, allowing remote authenticated users to impact confidentiality and integrity.
How do I fix CVE-2009-0977?
To fix CVE-2009-0977, you should apply the latest patches provided by Oracle for the affected database versions.
What versions of Oracle Database are affected by CVE-2009-0977?
CVE-2009-0977 affects Oracle Database versions 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3.
Who can exploit the CVE-2009-0977 vulnerability?
CVE-2009-0977 can be exploited by remote authenticated users with access to the Advanced Queuing component of the Oracle Database.
What component of Oracle Database does CVE-2009-0977 affect?
CVE-2009-0977 affects the Advanced Queuing component related to DBMS_AQIN within Oracle Database.