cbcvebase.
CVE-2008-3982
published 2008-10-14

CVE-2008-3982: Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3, and 11.1.0.6 allows remote…

PriorityP336medium5.5CVSS 2.0
AVNACLAuSCPIPAN
EXPLOIT
EPSS
11.43%
95.5th percentile
Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3, and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity, related to SYS.LT and WMSYS.LT, a different vulnerability than CVE-2008-3983 and CVE-2008-3984.

Affected

5 ranges
VendorProductVersion rangeFixed in
oracledatabase_10g
oracledatabase_10g
oracledatabase_11i
oracledatabase_9i
oracledatabase_9i

Detection & IOCsextracted from sources · hover to see the quote

processSYS.LT.COMPRESSWORKSPACE
  • Monitor for SQL injection attempts targeting the COMPRESSWORKSPACE procedure within the SYS.LT (or WMSYS.LT) PL/SQL package in Oracle Database.
  • Flag any remote authenticated Oracle DB user executing SYS.LT or WMSYS.LT procedures, particularly COMPRESSWORKSPACE, as this is the attack surface for CVE-2008-3982.
  • ·The vulnerability affects Oracle Database versions 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3, and 11.1.0.6 — scope detection rules to these specific versions.
  • ·Both SYS.LT and WMSYS.LT are listed as affected packages; detection and privilege auditing should cover both synonyms.
  • ·Exploitation requires only a remote authenticated user with EXECUTE privilege on the vulnerable package — low privilege bar means broad user population may be at risk.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.