CVE-2004-1707: High severity Oracle Application Server vulnerability
The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default path to find and execute library files while operating at raised privileges, which allows certain Oracle user accounts to gain root privileges via a modified libclntsh.so.9.0.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1707?
CVE-2004-1707 is considered to be a critical vulnerability due to its potential to allow unauthorized users to gain root privileges.
How do I fix CVE-2004-1707?
To fix CVE-2004-1707, it is recommended to update to a patched version of the affected Oracle software or adjust the library paths used by the dbsnmp and nmo programs to prevent the execution of modified libraries.
Which software is affected by CVE-2004-1707?
CVE-2004-1707 affects Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1 on Unix systems.
What impact does CVE-2004-1707 have on system security?
The impact of CVE-2004-1707 on system security is severe, as it allows certain Oracle user accounts to execute code with root privileges.
Is there a workaround for CVE-2004-1707?
Yes, as a workaround for CVE-2004-1707, users can modify the environment to limit the access to the library files utilized by Oracle's dbsnmp and nmo programs.