Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2004-1338


The triggers in Oracle 9i and 10g allow local users to gain privileges by using a sequence of partially privileged actions: using CCBKAPPLROWTRIG or EXEC_CBK_FN_DML to add arbitrary functions to the SDO_CMT_DBK_FN_TABLE and SDO_CMT_CBK_DML_TABLE, then performing a DELETE on the SDO_TXN_IDX_INSERTS table, which causes the SDO_CMT_CBK_TRIG trigger to execute the user-supplied functions.


Published

2004-12-23T05:00:00.000

Last Modified

2025-04-03T01:03:51.193

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 6.5 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application oracle database_server 10.2.1 Yes
Application oracle oracle9i 9.0 Yes
Application oracle oracle9i 9.0.1 Yes
Application oracle oracle9i 9.0.1.2 Yes
Application oracle oracle9i 9.0.1.3 Yes
Application oracle oracle9i 9.0.1.4 Yes
Application oracle oracle9i 9.0.2 Yes
Application oracle oracle9i 9.0.2.0.0 Yes
Application oracle oracle9i 9.0.2.0.1 Yes
Application oracle oracle9i 9.0.2.1 Yes
Application oracle oracle9i 9.0.2.2 Yes
Application oracle oracle9i 9.0.2.3 Yes
Application oracle oracle9i 9.2.0.1 Yes
Application oracle oracle9i 9.2.0.2 Yes

References