VulnerabilityModified
CVE-2002-0567
Oracle 8i and 9i with PL/SQL package for External Procedures (EXTPROC) allows remote attackers to bypass authentication and execute arbitrary functions by using the TNS Listener to directly connect to the EXTPROC process.
HIGH 7.5EPSS 8.74%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (8.74%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Oracle 8i and 9i with PL/SQL package for External Procedures (EXTPROC) allows remote attackers to bypass authentication and execute arbitrary functions by using the TNS Listener to directly connect to the EXTPROC process.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 8.74% probability · 95th percentile
- CISA KEV
- Not listed
- Affected
- oracle/database server · oracle/oracle8i · oracle/oracle9i
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=101301332402079&w=2
- http://otn.oracle.com/deploy/security/pdf/plsextproc_alert.pdfPatch, Vendor Advisory
- http://www.cert.org/advisories/CA-2002-08.htmlPatch, Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/180147US Government Resource
- http://www.securityfocus.com/bid/4033Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/8089
- http://marc.info/?l=bugtraq&m=101301332402079&w=2
- http://otn.oracle.com/deploy/security/pdf/plsextproc_alert.pdfPatch, Vendor Advisory
- http://www.cert.org/advisories/CA-2002-08.htmlPatch, Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/180147US Government Resource
- http://www.securityfocus.com/bid/4033Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/8089
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.