PT-2009-4434 · Oracle · Oracle Database

Published

2009-10-22

·

Updated

2018-10-10

·

CVE-2009-1979

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Oracle Database versions 10.1.0.5 through 10.2.0.4
Description: The issue affects the confidentiality, integrity, and availability of the system. It is related to the Network Authentication component. Details about real-world incidents where this issue was exploited are not provided. An independent researcher claims that the issue might be related to improper validation of the AUTH SESSKEY parameter length, potentially leading to arbitrary code execution.
Recommendations: For Oracle Database versions 10.1.0.5 through 10.2.0.4, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2009-1979

Affected Products

Oracle Database