{"api_version":"1","generated_at":"2026-07-23T12:21:41+00:00","cve":"CVE-2007-5511","urls":{"html":"https://cve.report/CVE-2007-5511","api":"https://cve.report/api/cve/CVE-2007-5511.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-5511","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-5511"},"summary":{"title":"CVE-2007-5511","description":"SQL injection vulnerability in Workspace Manager for Oracle Database before OWM 10.2.0.4.1, OWM 10.1.0.8.0, and OWM 9.2.0.8.0 allows attackers to execute arbitrary SQL commands via the FINDRICSET procedure in the LT package.  NOTE: this is probably covered by CVE-2007-5510, but there are insufficient details to be certain.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-10-17 23:17:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-89","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.5","severity":"","vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2007/3524","name":"http://www.vupen.com/english/advisories/2007/3524","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/40079","name":"http://osvdb.org/40079","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/482429/100/0/threaded","name":"http://www.securityfocus.com/archive/1/482429/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/4570","name":"https://www.exploit-db.com/exploits/4570","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Oracle 10g/11g - 'SYS.LT.FINDRICSET' SQL Injection (1) - Multiple local Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/27251","name":"http://secunia.com/advisories/27251","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Oracle Products Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/4571","name":"https://www.exploit-db.com/exploits/4571","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Oracle 10g/11g SYS.LT.FINDRICSET Local SQL Injection Exploit (2)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/27409","name":"http://secunia.com/advisories/27409","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"HP Oracle for OpenView Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=119332677525918&w=2","name":"http://marc.info/?l=bugtraq&m=119332677525918&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/4572","name":"https://www.exploit-db.com/exploits/4572","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Oracle 10g LT.FINDRICSET Local SQL Injection Exploit (IDS evasion)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1018823","name":"http://www.securitytracker.com/id?1018823","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Oracle Database and Other Products Have Unspecified Vulnerabilities With Unspecified Impact","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/3626","name":"http://www.vupen.com/english/advisories/2007/3626","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/3245","name":"http://securityreason.com/securityalert/3245","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"CXSecurity - IDS","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/26098","name":"http://www.securityfocus.com/bid/26098","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Oracle Workspace Manager LT Package SQL Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-5511","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-5511","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"5511","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"database_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T15:31:58.829Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20071017 SQL Injection Flaw in Oracle Workspace Manager","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/482429/100/0/threaded"},{"name":"ADV-2007-3524","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/3524"},{"name":"26098","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/26098"},{"name":"ADV-2007-3626","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/3626"},{"name":"4571","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/4571"},{"name":"SSRT061201","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=119332677525918&w=2"},{"name":"HPSBMA02133","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=119332677525918&w=2"},{"name":"4572","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/4572"},{"name":"40079","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/40079"},{"name":"1018823","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1018823"},{"name":"4570","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/4570"},{"name":"3245","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/3245"},{"name":"27409","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/27409"},{"name":"27251","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/27251"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-10-16T00:00:00.000Z","descriptions":[{"lang":"en","value":"SQL injection vulnerability in Workspace Manager for Oracle Database before OWM 10.2.0.4.1, OWM 10.1.0.8.0, and OWM 9.2.0.8.0 allows attackers to execute arbitrary SQL commands via the FINDRICSET procedure in the LT package.  NOTE: this is probably covered by CVE-2007-5510, but there are insufficient details to be certain."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-15T20:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20071017 SQL Injection Flaw in Oracle Workspace Manager","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/482429/100/0/threaded"},{"name":"ADV-2007-3524","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/3524"},{"name":"26098","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/26098"},{"name":"ADV-2007-3626","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/3626"},{"name":"4571","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/4571"},{"name":"SSRT061201","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=119332677525918&w=2"},{"name":"HPSBMA02133","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=119332677525918&w=2"},{"name":"4572","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/4572"},{"name":"40079","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/40079"},{"name":"1018823","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1018823"},{"name":"4570","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/4570"},{"name":"3245","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/3245"},{"name":"27409","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/27409"},{"name":"27251","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/27251"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-5511","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"SQL injection vulnerability in Workspace Manager for Oracle Database before OWM 10.2.0.4.1, OWM 10.1.0.8.0, and OWM 9.2.0.8.0 allows attackers to execute arbitrary SQL commands via the FINDRICSET procedure in the LT package.  NOTE: this is probably covered by CVE-2007-5510, but there are insufficient details to be certain."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20071017 SQL Injection Flaw in Oracle Workspace Manager","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/482429/100/0/threaded"},{"name":"ADV-2007-3524","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/3524"},{"name":"26098","refsource":"BID","url":"http://www.securityfocus.com/bid/26098"},{"name":"ADV-2007-3626","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/3626"},{"name":"4571","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/4571"},{"name":"SSRT061201","refsource":"HP","url":"http://marc.info/?l=bugtraq&m=119332677525918&w=2"},{"name":"HPSBMA02133","refsource":"HP","url":"http://marc.info/?l=bugtraq&m=119332677525918&w=2"},{"name":"4572","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/4572"},{"name":"40079","refsource":"OSVDB","url":"http://osvdb.org/40079"},{"name":"1018823","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1018823"},{"name":"4570","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/4570"},{"name":"3245","refsource":"SREASON","url":"http://securityreason.com/securityalert/3245"},{"name":"27409","refsource":"SECUNIA","url":"http://secunia.com/advisories/27409"},{"name":"27251","refsource":"SECUNIA","url":"http://secunia.com/advisories/27251"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-5511","datePublished":"2007-10-17T23:00:00.000Z","dateReserved":"2007-10-17T00:00:00.000Z","dateUpdated":"2024-08-07T15:31:58.829Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-10-17 23:17:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-89","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:database_server:*:*:*:*:*:*:*:*","matchCriteriaId":"4A77562B-D1A5-450D-9288-3FC7145E9292"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"5511","Ordinal":"1","Title":"CVE-2007-5511","CVE":"CVE-2007-5511","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"5511","Ordinal":"1","NoteData":"SQL injection vulnerability in Workspace Manager for Oracle Database before OWM 10.2.0.4.1, OWM 10.1.0.8.0, and OWM 9.2.0.8.0 allows attackers to execute arbitrary SQL commands via the FINDRICSET procedure in the LT package.  NOTE: this is probably covered by CVE-2007-5510, but there are insufficient details to be certain.","Type":"Description","Title":"CVE-2007-5511"},{"CveYear":"2007","CveId":"5511","Ordinal":"2","NoteData":"2007-10-17","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"5511","Ordinal":"3","NoteData":"2018-10-15","Type":"Other","Title":"Modified"}]}}}