CVE-2004-1338: Medium severity Oracle Oracle9i vulnerability
The triggers in Oracle 9i and 10g allow local users to gain privileges by using a sequence of partially privileged actions: using CCBKAPPLROWTRIG or EXECCBKFNDML to add arbitrary functions to the SDOCMTDBKFNTABLE and SDOCMTCBKDMLTABLE, then performing a DELETE on the SDOTXNIDXINSERTS table, which causes the SDOCMTCBKTRIG trigger to execute the user-supplied functions.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1338?
CVE-2004-1338 is considered a critical vulnerability as it allows local users to gain elevated privileges.
How do I fix CVE-2004-1338?
To fix CVE-2004-1338, you should apply the latest security patches provided by Oracle for the affected versions.
What products are affected by CVE-2004-1338?
CVE-2004-1338 affects various versions of Oracle 9i and Oracle Database 10g.
Can CVE-2004-1338 be exploited remotely?
CVE-2004-1338 cannot be exploited remotely as it requires local access to the affected system.
What are the potential impacts of CVE-2004-1338?
The potential impacts of CVE-2004-1338 include unauthorized access to sensitive data and the ability to execute arbitrary functions.