CVE-2009-0978 is an unspecified vulnerability within the Workspace Manager component of Oracle Database 10.2.0.4 and 11.1.0.6. This flaw allows remote authenticated users to compromise the confidentiality and integrity of the database through unknown vectors. With a CVSS score of 5.5, it is considered a medium severity vulnerability, requiring authentication but having low attack complexity, potentially leading to partial confidentiality and integrity impacts. While not in the KEV catalog or actively exploited, a Metasploit module exists for a related SQL injection, and it has minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.2.0.4CPE matchmatch criteria | cpe:2.3:a:oracle:database_10g:10.2.0.4:*:*:*:*:*:*:* | ||
11.1.0.6CPE matchmatch criteria | cpe:2.3:a:oracle:database_11g:11.1.0.6:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:P/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.