Description
Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.2 on Windows allows remote attackers to have an unknown impact, aka DB01. NOTE: as of 20070424, Oracle has not disputed reliable claims that this issue occurs because the NTLM SSPI AcceptSecurityContext function grants privileges based on the username provided even though all users are authenticated as Guest, which allows remote attackers to gain privileges.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T13:23:50.898Z
Reserved: 2007-04-18T00:00:00.000Z
Link: CVE-2007-2108
No data.
Status : Modified
Published: 2007-04-18T18:19:00.000
Modified: 2026-04-23T00:35:47.467
Link: CVE-2007-2108
No data.
OpenCVE Enrichment
No data.
Weaknesses