CVE-2005-0298: Medium severity Oracle Database Server vulnerability
The DIRECTORY objects in Oracle 8i through Oracle 10g contain the location of a specific operating system directory, which allows users with read privileges to a DIRECTORY object to obtain sensitive information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-0298?
CVE-2005-0298 is considered a medium severity vulnerability due to the exposure of sensitive directory information.
How do I fix CVE-2005-0298?
To fix CVE-2005-0298, ensure that users do not have read privileges on DIRECTORY objects or upgrade to a patched version of Oracle Database.
What versions of Oracle Database are affected by CVE-2005-0298?
CVE-2005-0298 affects Oracle Database versions 8i through 10g, including 8.0.6, 9.0.1, and 10.1.0.3.
What type of information can be exposed due to CVE-2005-0298?
CVE-2005-0298 can expose sensitive information such as file paths and directory locations on the operating system.
Who is at risk due to CVE-2005-0298?
Users with read privileges on DIRECTORY objects in the affected Oracle Database versions are at risk of exploiting CVE-2005-0298.