Unknown
CVE-2004-1370
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
Unknown
(0 users assessed)Unknown
(0 users assessed)Unknown
Unknown
Unknown
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
Multiple SQL injection vulnerabilities in PL/SQL procedures that run with definer rights in Oracle 9i and 10g allow remote attackers to execute arbitrary SQL commands and gain privileges via (1) DBMS_EXPORT_EXTENSION, (2) WK_ACL.GET_ACL, (3) WK_ACL.STORE_ACL, (4) WK_ADM.COMPLETE_ACL_SNAPSHOT, (5) WK_ACL.DELETE_ACLS_WITH_STATEMENT, or (6) DRILOAD.VALIDATE_STMT.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- application server,
- application server 9.0.2,
- application server 9.0.2.0.0,
- application server 9.0.2.0.1,
- application server 9.0.2.1,
- application server 9.0.2.2,
- application server 9.0.2.3,
- application server 9.0.3,
- application server 9.0.3.1,
- application server 9.0.4,
- application server 9.0.4.0,
- application server 9.0.4.1,
- collaboration suite release 1,
- e-business suite 11.5.1,
- e-business suite 11.5.2,
- e-business suite 11.5.3,
- e-business suite 11.5.4,
- e-business suite 11.5.5,
- e-business suite 11.5.6,
- e-business suite 11.5.7,
- e-business suite 11.5.8,
- e-business suite 11.5.9,
- enterprise manager 9,
- enterprise manager 9.0.1,
- enterprise manager database control 10.1.2,
- enterprise manager grid control 10.1.0.2,
- oracle10g enterprise 10.1.0.2,
- oracle10g enterprise 9.0.4 .0,
- oracle10g personal 10.1 .0.2,
- oracle10g personal 9.0.4 .0,
- oracle10g standard 10.1 .0.2,
- oracle10g standard 9.0.4 .0,
- oracle8i enterprise 8.0.5 .0.0,
- oracle8i enterprise 8.0.6 .0.0,
- oracle8i enterprise 8.0.6 .0.1,
- oracle8i enterprise 8.1.5 .0.0,
- oracle8i enterprise 8.1.5 .0.2,
- oracle8i enterprise 8.1.5 .1.0,
- oracle8i enterprise 8.1.6 .0.0,
- oracle8i enterprise 8.1.6 .1.0,
- oracle8i enterprise 8.1.7 .0.0,
- oracle8i enterprise 8.1.7 .1.0,
- oracle8i enterprise 8.1.7 .4,
- oracle8i standard 8.0.6,
- oracle8i standard 8.0.6 .3,
- oracle8i standard 8.1.5,
- oracle8i standard 8.1.6,
- oracle8i standard 8.1.7,
- oracle8i standard 8.1.7 .0.0,
- oracle8i standard 8.1.7 .1,
- oracle8i standard 8.1.7 .4,
- oracle9i client 9.2.0.1,
- oracle9i client 9.2.0.2,
- oracle9i enterprise 8.1.7,
- oracle9i enterprise 9.0.1,
- oracle9i enterprise 9.0.1.4,
- oracle9i enterprise 9.0.1.5,
- oracle9i enterprise 9.2.0,
- oracle9i enterprise 9.2.0.1,
- oracle9i enterprise 9.2.0.2,
- oracle9i enterprise 9.2.0.3,
- oracle9i enterprise 9.2.0.4,
- oracle9i enterprise 9.2.0.5,
- oracle9i personal 8.1.7,
- oracle9i personal 9.0.1,
- oracle9i personal 9.0.1.4,
- oracle9i personal 9.0.1.5,
- oracle9i personal 9.2,
- oracle9i personal 9.2.0.1,
- oracle9i personal 9.2.0.2,
- oracle9i personal 9.2.0.3,
- oracle9i personal 9.2.0.4,
- oracle9i personal 9.2.0.5,
- oracle9i standard 8.1.7,
- oracle9i standard 9.0,
- oracle9i standard 9.0.1,
- oracle9i standard 9.0.1.2,
- oracle9i standard 9.0.1.3,
- oracle9i standard 9.0.1.4,
- oracle9i standard 9.0.1.5,
- oracle9i standard 9.0.2,
- oracle9i standard 9.2,
- oracle9i standard 9.2.0.1,
- oracle9i standard 9.2.0.2,
- oracle9i standard 9.2.0.3,
- oracle9i standard 9.2.0.4,
- oracle9i standard 9.2.0.5
Weaknesses
References
Advisory
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: