← All CVEs

CVE-2009-1968

medium · 4.3

Unspecified vulnerability in the Secure Enterprise Search component in Oracle Database 10.1.8.3 allows remote attackers to affect integrity via unknown vectors. NOTE: the previous information was obtained from the July 2009 CPU. Oracle has not commented on claims from an established researcher that this is cross-site scripting (XSS) via the search_p_groups parameter in search/query/search.

4.3
CVSS
40.1%
EPSS (exploit prob.)
99th
EPSS percentile
2009-07-14
Published

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

VendorProductAffected versions
oracledatabase_server10.1.8.3

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2009-1968