CRITICAL · 9.8

CVE-2004-1363

Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via environment variables in the library name, which are expanded after the length check is performed.

Vulnerability Description

Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via environment variables in the library name, which are expanded after the length check is performed.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
OracleApplication ServerAll versions
OracleCollaboration Suite-
OracleDatabase Server8.1.7.4
OracleE-Business Suite11.5.1
OracleEnterprise Manager9
OracleEnterprise Manager Database Control10.1.2
OracleEnterprise Manager Grid Control10.1.0.2

Related Weaknesses (CWE)

References

FAQ

What is CVE-2004-1363?

CVE-2004-1363 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via environment variables in the library name, which are expanded after the length check is performed.

How severe is CVE-2004-1363?

CVE-2004-1363 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2004-1363?

Check the references section above for vendor advisories and patch information. Affected products include: Oracle Application Server, Oracle Collaboration Suite, Oracle Database Server, Oracle E-Business Suite, Oracle Enterprise Manager.