CVE-2008-3996

Oracle Database <11.1.0.6 - Info Disclosure

Title source: llm

Description

Unspecified vulnerability in the Change Data Capture component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity, related to SYS.DBMS_CDC_IPUBLISH.

Exploits (1)

metasploit WORKING POC
by MC · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/sqli/oracle/dbms_cdc_ipublish.rb

Scores

EPSS 0.3781
EPSS Percentile 97.2%

Details

Status published
Products (3)
oracle/database_10g 10.1.0.5
oracle/database_10g 10.2.0.4
oracle/database_11i 11.1.0.6
Published Oct 14, 2008
Tracked Since Feb 18, 2026