First published: Thu Oct 22 2009(Updated: )
Unspecified vulnerability in the Network Authentication component in Oracle Database 10.1.0.5 and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2009 CPU. Oracle has not commented on claims from an independent researcher that this is related to improper validation of the AUTH_SESSKEY parameter length that leads to arbitrary code execution.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Database | =10.2.0.4 | |
Oracle Database | =10.1.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2009-1979 is considered significant due to its potential impact on confidentiality, integrity, and availability.
To fix CVE-2009-1979, it is recommended to upgrade Oracle Database to a supported version that addresses the vulnerability.
CVE-2009-1979 affects Oracle Database versions 10.1.0.5 and 10.2.0.4.
Yes, CVE-2009-1979 can be exploited remotely by attackers to compromise the affected database.
The potential impacts of CVE-2009-1979 include unauthorized access and modification of data, leading to possible data breaches.