6.5

CVE-2004-1338

The triggers in Oracle 9i and 10g allow local users to gain privileges by using a sequence of partially privileged actions: using CCBKAPPLROWTRIG or EXEC_CBK_FN_DML to add arbitrary functions to the SDO_CMT_DBK_FN_TABLE and SDO_CMT_CBK_DML_TABLE, then performing a DELETE on the SDO_TXN_IDX_INSERTS table, which causes the SDO_CMT_CBK_TRIG trigger to execute the user-supplied functions.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OracleDatabase Server Version10.2.1 Updater2
OracleOracle9i Version9.0
OracleOracle9i Version9.0.1
OracleOracle9i Version9.0.1.2
OracleOracle9i Version9.0.1.3
OracleOracle9i Version9.0.1.4
OracleOracle9i Version9.0.2
OracleOracle9i Version9.0.2.0.0
OracleOracle9i Version9.0.2.0.1
OracleOracle9i Version9.0.2.1
OracleOracle9i Version9.0.2.2
OracleOracle9i Version9.0.2.3
OracleOracle9i Version9.2.0.1
OracleOracle9i Version9.2.0.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.505
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P