7.5

CVE-2005-4832

Exploit

SQL injection vulnerability in the Oracle Database Server 10g allows remote authenticated users to execute arbitrary SQL commands with elevated privileges via the SUBSCRIPTION_NAME parameter in the (1) SYS.DBMS_CDC_SUBSCRIBE and (2) SYS.DBMS_CDC_ISUBSCRIBE packages, a different vector than CVE-2005-1197.

Data is provided by the National Vulnerability Database (NVD)
OracleOracle10g Versionenterprise_9.0.4.0
OracleOracle10g Versionenterprise_9.0.4_.0
OracleOracle10g Versionenterprise_10.1.0.2
OracleOracle10g Versionenterprise_10.1.0.3
OracleOracle10g Versionenterprise_10.1.0.3.1
OracleOracle10g Versionenterprise_10.1.0.4
OracleOracle10g Versionenterprise_10.2.3
OracleOracle10g Versionpersonal_9.0.4.0
OracleOracle10g Versionpersonal_9.0.4_.0
OracleOracle10g Versionpersonal_10.1.0.2
OracleOracle10g Versionpersonal_10.1.0.3
OracleOracle10g Versionpersonal_10.1.0.3.1
OracleOracle10g Versionpersonal_10.1.0.4
OracleOracle10g Versionpersonal_10.1_.0.2
OracleOracle10g Versionpersonal_10.2.3
OracleOracle10g Versionpersonal_10.10.3.1
OracleOracle10g Versionstandard_9.0.4.0
OracleOracle10g Versionstandard_9.0.4_.0
OracleOracle10g Versionstandard_10.1.0.2
OracleOracle10g Versionstandard_10.1.0.3
OracleOracle10g Versionstandard_10.1.0.3.1
OracleOracle10g Versionstandard_10.1.0.4
OracleOracle10g Versionstandard_10.1.0.4.2
OracleOracle10g Versionstandard_10.1.0.5
OracleOracle10g Versionstandard_10.1_.0.2
OracleOracle10g Versionstandard_10.2.0.1
OracleOracle10g Versionstandard_10.2.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 52.59% 0.978
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P