CVE-2007-5561
Estado: ModificadaAlta (10)—
Format string vulnerability in the logging function in the Oracle OPMN daemon, as used on Oracle Enterprise Grid Console server 10.2.0.1, allows remote attackers to execute arbitrary code via format string specifiers in the URI in an HTTP request to port 6003, aka Oracle reference number 6296175. NOTE: this might be the same issue as CVE-2007-0282 or CVE-2007-0280, but there are insufficient details to be sure.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
- Puntuación base: 10
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 7.72%
- Percentil entre todas las CVEs puntuadas: 94
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-134
Referencias
- http://www.irmplc.com/index.php/111-Vendor-Alerts
- http://www.irmplc.com/index.php/142-Advisory-021
- http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html
- http://www.irmplc.com/index.php/111-Vendor-Alerts
- http://www.irmplc.com/index.php/142-Advisory-021
- http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html
JSON original (NVD)
Mostrar
{
"id": "CVE-2007-5561",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": true,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-10-18T20:17:00.000",
"references": [
{
"url": "http://www.irmplc.com/index.php/111-Vendor-Alerts",
"source": "cve@mitre.org"
},
{
"url": "http://www.irmplc.com/index.php/142-Advisory-021",
"tags": [
"Exploit",
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.irmplc.com/index.php/111-Vendor-Alerts",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.irmplc.com/index.php/142-Advisory-021",
"tags": [
"Exploit",
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-134"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Format string vulnerability in the logging function in the Oracle OPMN daemon, as used on Oracle Enterprise Grid Console server 10.2.0.1, allows remote attackers to execute arbitrary code via format string specifiers in the URI in an HTTP request to port 6003, aka Oracle reference number 6296175. NOTE: this might be the same issue as CVE-2007-0282 or CVE-2007-0280, but there are insufficient details to be sure."
},
{
"lang": "es",
"value": "Vulnerabilidad de cadena de formato en la función de registro del demonio Oracle OPMN, como se usa en Oracle Enterprise Grid Console server 10.2.0.1, permite a atacantes remotos ejecutar código de su elección mediante especificadores de cadena de formato en el URI de una petición HTTP al puerto 6003, también conocida como número de referencia de Oracle 6296175. NOTA: este podría ser el mismo problema que CVE-2007-0282 o CVE-1007-0280, pero no hay suficientes detalles para estar seguros."
}
],
"lastModified": "2026-06-16T22:46:24.003",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:oracle:enterprise_grid_console_server:10.2.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E2A642BD-D941-486E-9A9E-F81F2F756A9F"
},
{
"criteria": "cpe:2.3:a:oracle:opmn_daemon:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "68C4909D-7F6B-44DC-972D-9E73514FB613"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}