PT-2004-1729 · Oracle · Oracle Database Server
Published
2004-09-02
·
Updated
2008-09-10
·
CVE-2004-0637
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Oracle Database Server versions 8.1.7.4 through 9.2.0.4
Description
The issue allows local users to execute commands with additional privileges via the ctxsys.driload package, which is publicly accessible.
Recommendations
For Oracle Database Server versions 8.1.7.4 through 9.2.0.4, consider restricting access to the ctxsys.driload package to minimize the risk of exploitation.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oracle Database Server