PT-2002-1617 · Oracle · Oracle

Publicado

2002-07-03

·

Atualizado

2017-10-10

·

CVE-2002-0567

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Oracle versions 8i and 9i
Description The issue allows remote attackers to bypass authentication and execute arbitrary functions by using the TNS Listener to directly connect to the EXTPROC process, which is part of the PL/SQL package for External Procedures.
Recommendations For Oracle versions 8i and 9i, consider restricting access to the EXTPROC process to minimize the risk of exploitation. As a temporary workaround, consider disabling the EXTPROC process until a more permanent solution is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0567

Produtos afetados

Oracle