CVE-2011-0830Improper Handling of Syntactically Invalid Structure in Oracle Database Server

Severity
4.3MEDIUMNVD
EPSS
0.3%
top 45.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 20
Latest updateMay 17

Description

Unspecified vulnerability in the Event Management component in Oracle Database Server 10.1.0.5, 10.2.0.3, and 10.2.0.4, and Oracle Enterprise Manager Grid Control 10.1.0.6, allows remote attackers to affect integrity via unknown vectors related to Rules Management UI.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

NVDoracle/database_server10.1.0.5, 10.2.0.3, 10.2.0.4+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-9f9h-c85j-c3hw: Unspecified vulnerability in the Event Management component in Oracle Database Server 102022-05-17
CVEList
CVE-2011-0830: Unspecified vulnerability in the Event Management component in Oracle Database Server 102011-07-20

📋Vendor Advisories

2
Red Hat
php: remote code exec flaw introduced in the CVE-2011-4885 hashdos fix2012-02-02
Drupal
Hash DOS attack prevention with Suhosin needs a .htaccess edit - PSA-2012-0012012-01-11

💬Community

1
Bugzilla
CVE-2012-0830 php: remote code exec flaw introduced in the CVE-2011-4885 hashdos fix [fedora-all]2012-02-02
CVE-2011-0830 — Oracle Database Server vulnerability | cvebase