Local Privilege Escalation Vulnerability in Oracle Database Products
CVE-2004-1338
Currently unrated
Summary
A vulnerability exists in Oracle 9i and 10g that allows local users to escalate their privileges through a series of actions involving database triggers. By exploiting the triggers CCBKAPPLROWTRIG or EXEC_CBK_FN_DML, users can add arbitrary functions to critical database tables such as SDO_CMT_DBK_FN_TABLE and SDO_CMT_CBK_DML_TABLE. Subsequently, executing a DELETE command on the SDO_TXN_IDX_INSERTS table triggers the user-defined functions, giving unauthorized privileges. This vulnerability highlights the potential risks in privilege management and trigger implementation within Oracle databases.
References
Timeline
Vulnerability Reserved
Vulnerability published