CVE-2008-3983 EXPLOIT
5.5
MEDIUM · CVSS 2.0 · EPSS 41.8% (pctl 99)
Patch early
A public exploit exists.
Description
Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3, and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity, related to SYS.LT and WMSYS.LT, a different vulnerability than CVE-2008-3982 and CVE-2008-3984.
Scoring
| CVSS | 5.5 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
| EPSS | 41.81% — more likely to be exploited than 99% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-10-14 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| oracle | database 10g |
| oracle | database 11i |
| oracle | database 9i |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Oracle 10g - SYS.LT.MERGEWORKSPACE SQL Injection | 2009-01-06 |
References
- http://secunia.com/advisories/32291
- http://www.oracle.com/technetwork/topics/security/cpuoct2008-100299.html
- http://www.securitytracker.com/id?1021050
- http://www.vupen.com/english/advisories/2008/2825
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45886
- http://secunia.com/advisories/32291
- http://www.oracle.com/technetwork/topics/security/cpuoct2008-100299.html
- http://www.securitytracker.com/id?1021050
- http://www.vupen.com/english/advisories/2008/2825
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45886
→ the Explorer · watch your stack · NVD