CVE-2010-3594SQL Injection in Oracle Enterprise Manager Grid Control

3 documents3 sources
Severity
6.4MEDIUMNVD
EPSS
0.5%
top 32.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 19
Latest updateMay 17

Description

Unspecified vulnerability in the Real User Experience Insight component in Oracle Enterprise Manager Grid Control 6.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Processing. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from a reliable third party coordinator that this is SQL injection in rsynclogdird involving improper escaping of UTF-8 characters while processing log files.

CVSS vector

AV:N/AC:L/C:P/I:P/A:NExploitability: 10.0 | Impact: 4.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-75pm-pvvg-r2qr: Unspecified vulnerability in the Real User Experience Insight component in Oracle Enterprise Manager Grid Control 62022-05-17
CVEList
CVE-2010-3594: Unspecified vulnerability in the Real User Experience Insight component in Oracle Enterprise Manager Grid Control 62011-01-19
CVE-2010-3594 — SQL Injection in Oracle | cvebase