Oracle Database Server 8.1.7.4 through 9.2.0.4 allows local users to execute commands with additional privileges via the ctxsys.driload package, which is publicly accessible.
Software | From | Fixed in |
---|---|---|
oracle / oracle8i | enterprise_8.1.7_.4 | enterprise_8.1.7_.4.x |
oracle / oracle8i | standard_8.1.7_.4 | standard_8.1.7_.4.x |
oracle / oracle9i | enterprise_9.2.0.4 | enterprise_9.2.0.4.x |
oracle / oracle9i | personal_9.2.0.4 | personal_9.2.0.4.x |
oracle / oracle9i | standard_9.0.1.3 | standard_9.0.1.3.x |
oracle / oracle9i | standard_9.2.0.4 | standard_9.2.0.4.x |