CVE-2004-1707
The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default path to find and execute library files while operating at raised privileges, which allows certain Oracle user accounts to gain root…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.57%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default path to find and execute library files while operating at raised privileges, which allows certain Oracle user accounts to gain root privileges via a modified libclntsh.so.9.0.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 2.57% probability · 84th percentile
- CISA KEV
- Not listed
- Affected
- oracle/application server · oracle/application server portal · oracle/database server lite · oracle/oracle8i · oracle/oracle9i
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=109147677214087&w=2
- http://secunia.com/advisories/12205Exploit, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/10829Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16839
- http://marc.info/?l=bugtraq&m=109147677214087&w=2
- http://secunia.com/advisories/12205Exploit, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/10829Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16839
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.