PT-2009-4434 · Oracle · Oracle Database
Published
2009-10-22
·
Updated
2018-10-10
·
CVE-2009-1979
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Oracle Database versions 10.1.0.5 through 10.2.0.4
Description:
The issue affects the confidentiality, integrity, and availability of the system. It is related to the Network Authentication component. Details about real-world incidents where this issue was exploited are not provided. An independent researcher claims that the issue might be related to improper validation of the
AUTH SESSKEY parameter length, potentially leading to arbitrary code execution.Recommendations:
For Oracle Database versions 10.1.0.5 through 10.2.0.4, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Database