cbcvebase.
CVE-2007-3854
published 2007-07-18

CVE-2007-3854: Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.5 allow remote authenticated users to have unknown impact via (1)…

PriorityP426medium5.5CVSS 2.0
AVNACLAuSCPIPAN
EPSS
2.53%
83.1th percentile
Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.5 allow remote authenticated users to have unknown impact via (1) SYS.DBMS_PRVTAQIS in the Advanced Queuing component (DB02) and (2) MDSYS.MD in the Spatial component (DB12). NOTE: Oracle has not disputed reliable researcher claims that DB02 is for SQL injection and DB12 is for a buffer overflow.

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
oracleapex
oracleapex
oracleapex
oracleapex
oracleapplication_server
oracleapplication_server
oracleapplication_server
oracleapplication_server
oracleapplication_server
oracleapplication_server
oracleapplication_server
oracleapplication_server
oracleapplication_server
oracleapplication_server
oraclecollaboration_suite
oracledatabase_server
oracledatabase_server
oracledatabase_server
oracledatabase_server
oracledatabase_server
oracledatabase_server
oracledatabase_server
oraclee-business_suite
oraclee-business_suite
oraclee-business_suite
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.