← Back

CVE-2009-1991

nvd nist
Published: Oct 22, 2009Modified: Apr 23, 2026

JSON object

Loading...
3.6
Vector
AV:N/AC:H/Au:S/C:P/I:P/A:N
Exploitability: 3.9 / Impact: 4.9
Source: NVD

Description

Unspecified vulnerability in the Oracle Text component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity, related to CTXSYS.DRVXTABC. NOTE: the previous information was obtained from the October 2009 CPU. Oracle has not commented on claims from an established researcher that this is for multiple SQL injection vulnerabilities via the (1) idx_owner or (2) idx_name parameters to the create_tables procedure.

Affected (4)

1 product
Database Server
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 10.1.0.5
Version 10.2.0.4
Version 9.2.0.8
Version 9.2.0.8dv

References (12)

Source: secalert_us@oracle.com
Source: secalert_us@oracle.com
Source: secalert_us@oracle.com
Source: secalert_us@oracle.com
Source: secalert_us@oracle.com
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource

Timeline

No history available yet.