CVE-2008-3983 is an unspecified vulnerability within the Workspace Manager component of Oracle Database versions 9.2.0.8, 10.1.0.5, 10.2.0.3, and 11.1.0.6. This vulnerability allows remote authenticated users to compromise both the confidentiality and integrity of the affected database. With a CVSS score of 5.5, it has a low attack complexity and requires authentication, but can lead to partial loss of confidentiality and integrity. While not listed in CISA's KEV catalog, exploit intelligence indicates the existence of a Metasploit module and an ExploitDB entry (EDB-7676) for a SQL injection via SYS.LT.MERGEWORKSPACE, suggesting exploitability. Despite this, there is no evidence of active exploitation, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.1.0.5CPE matchmatch criteria | cpe:2.3:a:oracle:database_10g:10.1.0.5:*:*:*:*:*:*:* | ||
10.2.0.3CPE matchmatch criteria | cpe:2.3:a:oracle:database_10g:10.2.0.3:*:*:*:*:*:*:* | ||
11.1.0.6CPE matchmatch criteria | cpe:2.3:a:oracle:database_11i:11.1.0.6:*:*:*:*:*:*:* | ||
9.2.0.8CPE matchmatch criteria | cpe:2.3:a:oracle:database_9i:9.2.0.8:*:*:*:*:*:*:* | ||
9.2.0.8dvCPE matchmatch criteria | cpe:2.3:a:oracle:database_9i:9.2.0.8dv:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:P/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.