First published: Thu Feb 10 2005(Updated: )
The DIRECTORY objects in Oracle 8i through Oracle 10g contain the location of a specific operating system directory, which allows users with read privileges to a DIRECTORY object to obtain sensitive information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Database | =8.0.6 | |
Oracle Database | =8.0.6.3 | |
Oracle Database | =8.1.7.4 | |
Oracle Database | =9.0.1.4 | |
Oracle Database | =9.0.1.5 | |
Oracle Database | =9.0.4 | |
Oracle Database | =9.2.0.4 | |
Oracle Database | =9.2.0.5 | |
Oracle Database | =9.2.0.6 | |
Oracle Database | =10.1.0.2 | |
Oracle Database | =10.1.0.3 | |
Oracle Database | =10.1.0.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0298 is considered a medium severity vulnerability due to the exposure of sensitive directory information.
To fix CVE-2005-0298, ensure that users do not have read privileges on DIRECTORY objects or upgrade to a patched version of Oracle Database.
CVE-2005-0298 affects Oracle Database versions 8i through 10g, including 8.0.6, 9.0.1, and 10.1.0.3.
CVE-2005-0298 can expose sensitive information such as file paths and directory locations on the operating system.
Users with read privileges on DIRECTORY objects in the affected Oracle Database versions are at risk of exploiting CVE-2005-0298.