SQL Injection Vulnerabilities in Oracle Database Products
CVE-2004-1370
Currently unrated
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 4 August 2004
Summary
Multiple SQL injection vulnerabilities exist within PL/SQL procedures in Oracle Database versions 9i and 10g. These vulnerabilities arise when procedures operate with definer rights, allowing remote attackers to execute arbitrary SQL commands. Affected procedures include DBMS_EXPORT_EXTENSION, WK_ACL.GET_ACL, WK_ACL.STORE_ACL, WK_ADM.COMPLETE_ACL_SNAPSHOT, WK_ACL.DELETE_ACLS_WITH_STATEMENT, and DRILOAD.VALIDATE_STMT. Exploiting these vulnerabilities can enable attackers to elevate privileges, posing significant security risks to the affected systems.
References
Timeline
Vulnerability Reserved
Vulnerability published