First published: Wed Jul 20 2011(Updated: )
Unspecified vulnerability in the Security Framework component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.1, and 11.2.0.2; and Oracle Enterprise Manager Grid Control 10.1.0.6 and 10.2.0.5; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to User Model.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Database | =10.1.0.5 | |
Oracle Database | =10.2.0.3 | |
Oracle Database | =10.2.0.4 | |
Oracle Database | =10.2.0.5 | |
Oracle Database | =11.1.0.7 | |
Oracle Database | =11.2.0.1 | |
Oracle Database | =11.2.0.2 | |
Oracle Enterprise Manager Grid Control 10g | =10.1.0.6 | |
Oracle Enterprise Manager Grid Control 10g | =10.2.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0848 has a high severity rating as it allows remote attackers to affect confidentiality, integrity, and availability of the affected systems.
To fix CVE-2011-0848, upgrade to the latest versions of Oracle Database Server or Oracle Enterprise Manager Grid Control provided by Oracle.
CVE-2011-0848 affects Oracle Database Server versions 10.1.0.5, 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.1, 11.2.0.2 and Oracle Enterprise Manager Grid Control versions 10.1.0.6 and 10.2.0.5.
CVE-2011-0848 allows remote attackers to conduct unauthorized actions that can compromise system confidentiality, integrity, and availability.
As of now, there are no publicly available details about specific exploits for CVE-2011-0848, but it poses a significant risk if left unaddressed.