SQL Injection Vulnerabilities in Oracle Database Products
CVE-2004-1370

Currently unrated

Key Information:

Vendor
Oracle
Vendor
CVE Published:
4 August 2004

Summary

Multiple SQL injection vulnerabilities exist within PL/SQL procedures in Oracle Database versions 9i and 10g. These vulnerabilities arise when procedures operate with definer rights, allowing remote attackers to execute arbitrary SQL commands. Affected procedures include DBMS_EXPORT_EXTENSION, WK_ACL.GET_ACL, WK_ACL.STORE_ACL, WK_ADM.COMPLETE_ACL_SNAPSHOT, WK_ACL.DELETE_ACLS_WITH_STATEMENT, and DRILOAD.VALIDATE_STMT. Exploiting these vulnerabilities can enable attackers to elevate privileges, posing significant security risks to the affected systems.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.