CVE-2006-0547 describes a critical vulnerability in Oracle Database 8i, 9i, and 10g that allows remote authenticated users to execute arbitrary SQL statements as the SYS user, bypassing audit logging. This high-severity flaw, with a CVSS score of 7.5, permits attackers to create new privileged database accounts and potentially compromise the entire database. While no public exploit intelligence or community discussion is available, the lack of a definitive patch confirmation from Oracle at the time of its disclosure raises concerns about its potential persistence.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.1.7.4CPE matchmatch criteria | cpe:2.3:a:oracle:database_server:8.1.7.4:r3:*:*:*:*:*:* | ||
9.2.0.6CPE matchmatch criteria | cpe:2.3:a:oracle:database_server:9.2.0.6:r2:*:*:*:*:*:* | ||
9.2.0.7CPE matchmatch criteria | cpe:2.3:a:oracle:database_server:9.2.0.7:r2:*:*:*:*:*:* | ||
10.1.0.3CPE matchmatch criteria | cpe:2.3:a:oracle:database_server:10.1.0.3:r1:*:*:*:*:*:* | ||
10.1.0.4CPE matchmatch criteria | cpe:2.3:a:oracle:database_server:10.1.0.4:r1:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.