vendor:
Oracle Database 11g Release 2
by:
Nguyen Khang - SunCSR
7.8
CVSS
HIGH
Unquoted Service Path
22
CWE
Product Name: Oracle Database 11g Release 2
Affected Version From: 11g release 2
Affected Version To: 11g release 2
Patch Exists: NO
Related CWE: N/A
CPE: oracle:oracle_database:11.2.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Pro x64 10.0.18363 N/A Build 18363
2020
Oracle Database 11g Release 2 – ‘OracleDBConsoleorcl’ Unquoted Service Path
Oracle Database 11g Release 2 is vulnerable to Unquoted Service Path vulnerability. This vulnerability allows an attacker to gain elevated privileges on the system. The vulnerability exists due to the OracleDBConsoleorcl, OracleOraDb11g_home1TNSListener and OracleServiceORCL services not having their paths quoted. An attacker can exploit this vulnerability by injecting malicious code into the unquoted service path.
Mitigation:
Ensure that all service paths are quoted. This can be done by setting the StartName registry value to a quoted path.