Command Execution Vulnerability in Oracle Database Product
CVE-2004-1365

Currently unrated

Key Information:

Vendor
Oracle
Vendor
CVE Published:
4 August 2004

Summary

The Extproc feature in Oracle Database versions 9i and 10g is vulnerable as it does not require authentication for loading libraries or executing functions. This weakness allows local users to execute arbitrary commands under the privileges of the Oracle user, potentially leading to escalated privileges and significant security breaches. With the absence of proper access controls in this mechanism, it poses a critical risk to database integrity and system security. Organizations using these affected versions should consider implementing immediate mitigations and upgrading to secure versions.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.