Description
Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.5 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB07 in the Dictionary component and (2) DB14 in the Oracle Label Security component. NOTE: Oracle has not disputed reliable researcher claims that DB07 involves plaintext storage of the TDE wallet password in a trace file by event 10053.
Remediation
References
Related Vulnerabilities
WordPress Plugin Recently Multiple Vulnerabilities (3.0.4)
WordPress Plugin Frontend File Manager Arbitrary File Upload (3.7)
WordPress Plugin WP-FaceThumb 'pagination_wp_facethumb' Parameter Cross-Site Scripting (0.1)
WordPress Cleartext Storage of Sensitive Information Vulnerability (CVE-2017-14990)
Oracle JRE Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-10356)