Command Execution Vulnerability in Oracle Database Product
CVE-2004-1365
Currently unrated
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 4 August 2004
Summary
The Extproc feature in Oracle Database versions 9i and 10g is vulnerable as it does not require authentication for loading libraries or executing functions. This weakness allows local users to execute arbitrary commands under the privileges of the Oracle user, potentially leading to escalated privileges and significant security breaches. With the absence of proper access controls in this mechanism, it poses a critical risk to database integrity and system security. Organizations using these affected versions should consider implementing immediate mitigations and upgrading to secure versions.
References
Timeline
Vulnerability Reserved
Vulnerability published