vendor:
Oracle Database Server
by:
SecurityFocus
8.5
CVSS
HIGH
Oracle Database Server Directory Traversal
22
CWE
Product Name: Oracle Database Server
Affected Version From: Oracle 9.0
Affected Version To: Oracle 9.0
Patch Exists: YES
Related CWE: N/A
CPE: oracle:database_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2004
Oracle Database Server Directory Traversal
Oracle Database server is reported to be vulnerable to multiple directory traversal vulnerabilities that may allow a remote attacker to read, write, or rename arbitrary files with the privileges of the Oracle Database server. This is due to a lack of sufficient input validation performed on filenames and paths passed to file processing functions, and may allow a malicious SQL query to traverse outside of a directory that is described in an Oracle directory object. Examples of malicious SQL queries are provided in the text.
Mitigation:
Oracle recommends that customers apply the latest Critical Patch Update as it contains fixes for these issues.