The package XDB.DBMS_XDBZ0 contains SQL injection vulnerabilities in the procedure enable_hierarchy_internal [DB01], disable_hierarchiy_internal [DB15]. Oracle fixed this problem by using bind variables and verifying table names.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/51386/Oracle-XDB.DBMS_XDBZ0.txt
Source: https://packetstormsecurity.com/files/51386/Oracle-XDB.DBMS_XDBZ0.txt.html