Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2008-0339Oracle Database Server vulnerability

4 documents4 sources
Severity
10.0CRITICALNVD
EPSS
27.2%
top 3.60%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJan 17
Latest updateMay 1

Description

Unspecified vulnerability in the XML DB component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 has unknown impact and remote attack vectors, aka DB01.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

NVDoracle/database_server10.1.0.5, 10.2.0.3, 9.2.0.8dv+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-p99c-5q2c-93xv: Unspecified vulnerability in the XML DB component in Oracle Database 92022-05-01
CVEList
CVE-2008-0339: Unspecified vulnerability in the XML DB component in Oracle Database 92008-01-17

💥Exploits & PoCs

1
Exploit-DB
Oracle Database 10 g - XML DB xdb.xdb_pitrig_pkg Package PITRIG_TRUNCATE Function Overflow2008-01-10
CVE-2008-0339 — Oracle Database Server vulnerability | cvebase