Unspecified Vulnerability in Oracle Database APEX Component
CVE-2009-0981

Currently unrated

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 April 2009

Summary

An unspecified vulnerability in the Application Express component of Oracle Database 11.1.0.7 allows remote authenticated users to potentially compromise confidentiality. This issue may enable the exposure of APEX password hashes from the WWV_FLOW_USERS table through unauthorized SELECT statements. Addressing this vulnerability is critical to safeguarding sensitive user data stored within the database.

References

EPSS Score

17% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.