Command Execution Vulnerability in Oracle Database Product
CVE-2004-1365
Currently unrated
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 4 August 2004
What is CVE-2004-1365?
The Extproc feature in Oracle Database versions 9i and 10g is vulnerable as it does not require authentication for loading libraries or executing functions. This weakness allows local users to execute arbitrary commands under the privileges of the Oracle user, potentially leading to escalated privileges and significant security breaches. With the absence of proper access controls in this mechanism, it poses a critical risk to database integrity and system security. Organizations using these affected versions should consider implementing immediate mitigations and upgrading to secure versions.