peter bassill · operator
$ cve CVE-2009-1968 JSON

CVE-2009-1968 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 40.1% (pctl 99)

Patch early

A public exploit exists.

Description

Unspecified vulnerability in the Secure Enterprise Search component in Oracle Database 10.1.8.3 allows remote attackers to affect integrity via unknown vectors. NOTE: the previous information was obtained from the July 2009 CPU. Oracle has not commented on claims from an established researcher that this is cross-site scripting (XSS) via the search_p_groups parameter in search/query/search.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS40.08% — more likely to be exploited than 99% of all CVEs
On CISA KEVno
Public exploityes
Published2009-07-14
Last modified2026-06-16

Affected (1)

VendorProduct
oracledatabase server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD