PT-2005-1741 · Oracle · Oracle Database Server
Cesar Cerrudo
·
Published
2005-03-07
·
Updated
2016-10-18
·
CVE-2005-0701
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle Database Server versions 8i and 9i
Description
A directory traversal issue allows remote attackers to read or rename arbitrary files via modified dot dot backslash sequences to UTL FILE functions, such as
UTL FILE.FOPEN or UTL FILE.frename.Recommendations
For Oracle Database Server version 8i, update to a version that includes the fix for this issue.
For Oracle Database Server version 9i, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the UTL FILE functions, such as
UTL FILE.FOPEN and UTL FILE.frename, until a patch is available.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Database Server