First published: Tue Nov 12 2002(Updated: )
Buffer overflow in Oracle iSQL*Plus web application of the Oracle 9 database server allows remote attackers to execute arbitrary code via a long USERID parameter in the isqlplus URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Database | =9.0.1 | |
Oracle Database | =9.0.2 | |
Oracle Database | =release_2_9.2.1 | |
Oracle Database | =9.0 | |
Oracle Database | =release_2_9.2.2 | |
Oracle Database | =9.0.1.3 | |
Oracle Database | =9.0.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1264 is classified as a critical security vulnerability due to the potential for remote code execution.
To fix CVE-2002-1264, apply the latest security patches provided by Oracle for the affected Oracle 9i versions.
CVE-2002-1264 affects several versions of Oracle 9i, including 9.0.1, 9.0.2, and various 9.2.x releases.
CVE-2002-1264 can allow remote attackers to execute arbitrary code, compromising the confidentiality, integrity, and availability of the system.
While CVE-2002-1264 is an older vulnerability, if an organization is still using affected Oracle 9i versions, it remains a significant security risk.