CVE-2009-1991: SQL Injection
Unspecified vulnerability in the Oracle Text component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity, related to CTXSYS.DRVXTABC. NOTE: the previous information was obtained from the October 2009 CPU. Oracle has not commented on claims from an established researcher that this is for multiple SQL injection vulnerabilities via the (1) idxowner or (2) idxname parameters to the createtables procedure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1991?
CVE-2009-1991 is considered to have critical severity due to its impact on confidentiality and integrity.
How do I fix CVE-2009-1991?
To fix CVE-2009-1991, apply the latest patches provided by Oracle for affected versions.
Which versions of Oracle Database are affected by CVE-2009-1991?
CVE-2009-1991 affects Oracle Database versions 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.4.
Who can exploit CVE-2009-1991?
CVE-2009-1991 can be exploited by remote authenticated users.
What components are involved in CVE-2009-1991?
CVE-2009-1991 is related to the Oracle Text component and specifically involves the CTXSYS.DRVXTABC.