AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2007-2108

MEDIUM · CVSS 6.8 EPSS 21.50%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2007-04-18 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.8. It affects Windows, Oracle. Its EPSS score suggests a 21.5% probability of exploitation in the next 30 days. It may be remotely exploitable.

CVE
CVE-2007-2108
Severity
MEDIUM
CVSS
6.8
EPSS
21.50%
Windows Oracle

Original NVD Description

Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.2 on Windows allows remote attackers to have an unknown impact, aka DB01. NOTE: as of 20070424, Oracle has not disputed reliable claims that this issue occurs because the NTLM SSPI AcceptSecurityContext function grants privileges based on the username provided even though all users are authenticated as Guest, which allows remote attackers to gain privileges.