Description
Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to have an unknown impact via (1) SYS.DBMS_DRS in the DataGuard component (DB03), (2) SYS.DBMS_STANDARD in the PL/SQL component (DB10), (3) MDSYS.RTREE_IDX in the Spatial component (DB16), and (4) SQL Compiler (DB17). NOTE: a reliable researcher claims that DB17 is for using Views to perform unauthorized insert, update, or delete actions.
Remediation
References
Related Vulnerabilities
WordPress Plugin Limit Login Attempts Reloaded Security Bypass (2.17.3)
WordPress Plugin Booking Calendar-Appointment Booking-BookIt Security Bypass (2.3.7)
WordPress Plugin Car Seller-Auto Classifieds Script SQL Injection (2.1.0)
AngularJS Inefficient Regular Expression Complexity Vulnerability (CVE-2023-26118)