peter bassill · operator
$ cve CVE-2007-5511 JSON

CVE-2007-5511 EXPLOIT

6.5
MEDIUM · CVSS 2.0 · EPSS 31.8% (pctl 98)

Patch early

A public exploit exists.

Description

SQL injection vulnerability in Workspace Manager for Oracle Database before OWM 10.2.0.4.1, OWM 10.1.0.8.0, and OWM 9.2.0.8.0 allows attackers to execute arbitrary SQL commands via the FINDRICSET procedure in the LT package. NOTE: this is probably covered by CVE-2007-5510, but there are insufficient details to be certain.

Scoring

CVSS6.5 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS31.76% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2007-10-17
Last modified2026-06-16

Affected (1)

VendorProduct
oracledatabase server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD