Vulnerability CVE-2000-0818


Published: 2000-12-19   Modified: 2012-02-12

Description:
The default installation for the Oracle listener program 7.3.4, 8.0.6, and 8.1.6 allows an attacker to cause logging information to be appended to arbitrary files and execute commands via the SET TRC_FILE or SET LOG_FILE commands.

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Oracle -> Listener 

 References:
http://otn.oracle.com/deploy/security/pdf/listener_alert.pdf
http://xforce.iss.net/alerts/advise66.php
https://exchange.xforce.ibmcloud.com/vulnerabilities/5380

Copyright 2024, cxsecurity.com

 

Back to Top