Local Privilege Escalation Vulnerability in Oracle Database Products
CVE-2004-1338

Currently unrated

Key Information:

Vendor
Oracle
Vendor
CVE Published:
23 December 2004

Summary

A vulnerability exists in Oracle 9i and 10g that allows local users to escalate their privileges through a series of actions involving database triggers. By exploiting the triggers CCBKAPPLROWTRIG or EXEC_CBK_FN_DML, users can add arbitrary functions to critical database tables such as SDO_CMT_DBK_FN_TABLE and SDO_CMT_CBK_DML_TABLE. Subsequently, executing a DELETE command on the SDO_TXN_IDX_INSERTS table triggers the user-defined functions, giving unauthorized privileges. This vulnerability highlights the potential risks in privilege management and trigger implementation within Oracle databases.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.