6.5

CVE-2004-1338

The triggers in Oracle 9i and 10g allow local users to gain privileges by using a sequence of partially privileged actions: using CCBKAPPLROWTRIG or EXEC_CBK_FN_DML to add arbitrary functions to the SDO_CMT_DBK_FN_TABLE and SDO_CMT_CBK_DML_TABLE, then performing a DELETE on the SDO_TXN_IDX_INSERTS table, which causes the SDO_CMT_CBK_TRIG trigger to execute the user-supplied functions.

Data is provided by the National Vulnerability Database (NVD)
OracleDatabase Server Version10.2.1 Updater2
OracleOracle9i Version9.0
OracleOracle9i Version9.0.1
OracleOracle9i Version9.0.1.2
OracleOracle9i Version9.0.1.3
OracleOracle9i Version9.0.1.4
OracleOracle9i Version9.0.2
OracleOracle9i Version9.0.2.0.0
OracleOracle9i Version9.0.2.0.1
OracleOracle9i Version9.0.2.1
OracleOracle9i Version9.0.2.2
OracleOracle9i Version9.0.2.3
OracleOracle9i Version9.2.0.1
OracleOracle9i Version9.2.0.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.3% 0.505
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P