Oracle Multiple Unspecified Vulnerabilities

BID:10871

Info

Oracle Multiple Unspecified Vulnerabilities

Bugtraq ID: 10871
Class: Unknown
CVE: CVE-2004-1362
CVE-2004-1364
CVE-2004-1365
CVE-2004-1366
CVE-2004-1368
CVE-2004-1369
Remote: Yes
Local: No
Published: Aug 04 2004 12:00AM
Updated: Jul 06 2016 02:40PM
Credit: David Litchfield, Michael Litchfield, Cesar Cerrudo, Esteban Martinez Fayo, Pete Finnigan, Jonathan Gennick, Alexander Kornbrust, Stephen Kost, Matt Moore, Aaron Newman, Andy Rees, and Christian Schaller, are credited for the discovery of these vulnerabili
Vulnerable: Sun SunMC 3.5 update 1a
Sun SunMC 3.5 update 1
Oracle Oracle9i Standard Edition 9.2 .3
Oracle Oracle9i Standard Edition 9.2 .0.5
Oracle Oracle9i Standard Edition 9.2 .0.3
Oracle Oracle9i Standard Edition 9.2 .0.2
Oracle Oracle9i Standard Edition 9.2 .0.1
Oracle Oracle9i Standard Edition 9.2
Oracle Oracle9i Standard Edition 9.0.2
Oracle Oracle9i Standard Edition 9.0.1 .5
Oracle Oracle9i Standard Edition 9.0.1 .4
Oracle Oracle9i Standard Edition 9.0.1 .3
Oracle Oracle9i Standard Edition 9.0.1 .2
Oracle Oracle9i Standard Edition 9.0.1
Oracle Oracle9i Standard Edition 9.0 .2.4
Oracle Oracle9i Standard Edition 9.0
Oracle Oracle9i Standard Edition 8.1.7
Oracle Oracle9i Personal Edition 9.2 .0.5
Oracle Oracle9i Personal Edition 9.2 .0.3
Oracle Oracle9i Personal Edition 9.2 .0.2
Oracle Oracle9i Personal Edition 9.2 .0.1
Oracle Oracle9i Personal Edition 9.2
Oracle Oracle9i Personal Edition 9.0.1 .5
Oracle Oracle9i Personal Edition 9.0.1 .4
Oracle Oracle9i Personal Edition 9.0.1
Oracle Oracle9i Personal Edition 9.0 .2.4
Oracle Oracle9i Personal Edition 8.1.7
Oracle Oracle9i Lite 5.0 .2.9.0
Oracle Oracle9i Lite 5.0 .2.0.0
Oracle Oracle9i Lite 5.0 .1.0.0
Oracle Oracle9i Lite 5.0 .0.0.0
Oracle Oracle9i Enterprise Edition 9.2 .2
Oracle Oracle9i Enterprise Edition 9.2 .0.5
Oracle Oracle9i Enterprise Edition 9.2 .0.3
Oracle Oracle9i Enterprise Edition 9.2 .0.1
Oracle Oracle9i Enterprise Edition 9.2 .0
Oracle Oracle9i Enterprise Edition 9.0.1 .5
Oracle Oracle9i Enterprise Edition 9.0.1 .4
Oracle Oracle9i Enterprise Edition 9.0.1
Oracle Oracle9i Enterprise Edition 9.0 .2.4
Oracle Oracle9i Enterprise Edition 8.1.7
Oracle Oracle9i Client Edition 9.2 .0.2
Oracle Oracle9i Client Edition 9.2 .0.1
Oracle Oracle9i Application Server Web Cache 9.0.3 .1
Oracle Oracle9i Application Server Web Cache 9.0.2 .3
Oracle Oracle9i Application Server Web Cache 9.0.2 .2
+ Oracle iStore 11i 11i.IBE.O
Oracle Oracle9i Application Server Reports 9.0.2 .1
Oracle Oracle9i Application Server Reports 9.0.2
Oracle Oracle9i Application Server Portal 9.0.2 .3B
Oracle Oracle9i Application Server Portal 9.0.2 .3A
+ Oracle Oracle9i Application Server 9.0.2 .2
Oracle Oracle9i Application Server Portal 9.0.2 .3
Oracle Oracle9i Application Server 9.0.3 .1
Oracle Oracle9i Application Server 9.0.3
Oracle Oracle9i Application Server 9.0.2 .3
Oracle Oracle9i Application Server 9.0.2 .2
Oracle Oracle9i Application Server 9.0.2 .1
Oracle Oracle9i Application Server 9.0.2 .0.1
Oracle Oracle9i Application Server 9.0.2 .0.0
Oracle Oracle9i Application Server 9.0.2
Oracle Oracle9i Application Server
Oracle Oracle8i Standard Edition 8.1.7 .4
Oracle Oracle8i Standard Edition 8.1.7 .1
Oracle Oracle8i Standard Edition 8.1.7 .0.0
Oracle Oracle8i Standard Edition 8.1.7
Oracle Oracle8i Standard Edition 8.1.6
Oracle Oracle8i Standard Edition 8.1.5
Oracle Oracle8i Standard Edition 8.0.6 .3
Oracle Oracle8i Standard Edition 8.0.6
Oracle Oracle8i Enterprise Edition 8.1.7 .4.0
Oracle Oracle8i Enterprise Edition 8.1.7 .1.0
Oracle Oracle8i Enterprise Edition 8.1.7 .0.0
Oracle Oracle8i Enterprise Edition 8.1.6 .1.0
Oracle Oracle8i Enterprise Edition 8.1.6 .0.0
Oracle Oracle8i Enterprise Edition 8.1.5 .1.0
Oracle Oracle8i Enterprise Edition 8.1.5 .0.2
Oracle Oracle8i Enterprise Edition 8.1.5 .0.0
Oracle Oracle8i Enterprise Edition 8.0.6 .0.1
Oracle Oracle8i Enterprise Edition 8.0.6 .0.0
Oracle Oracle8i Enterprise Edition 8.0.5 .0.0
Oracle Oracle8 8.1.7
- Microsoft Windows 2000 Professional
Oracle Oracle8 8.1.6
Oracle Oracle8 8.1.5
Oracle Oracle8 8.0.6
Oracle Oracle8 8.0.5 .1
Oracle Oracle8 8.0.5
- SGI IRIX 6.5.4
Oracle Oracle8 8.0.4
Oracle Oracle8 8.0.3
Oracle Oracle8 8.0.2
Oracle Oracle8 8.0.1
- HP HP-UX 11.0
- Microsoft Windows NT 4.0
- Sun Solaris 8_sparc
Oracle Oracle10g Standard Edition 10.1 .0.2
Oracle Oracle10g Standard Edition 9.0.4 .0
Oracle Oracle10g Personal Edition 10.1 .0.2
Oracle Oracle10g Personal Edition 9.0.4 .0
Oracle Oracle10g Enterprise Edition 10.1 .0.2
Oracle Oracle10g Enterprise Edition 9.0.4 .0
Oracle Oracle10g Application Server 10.1 .0.2
Oracle Oracle10g Application Server 9.0.4 .0
Oracle Oracle HTTP Server 9.2 .0
+ Apache Software Foundation Apache 1.3.22
Oracle Oracle HTTP Server 9.0.1
Oracle Oracle HTTP Server 8.1.7
+ Apache Software Foundation Apache 1.3.12
+ Oracle Oracle8 8.1.7
+ Oracle Oracle8i Enterprise Edition 8.1.7 .0.0
+ Oracle Oracle8i Standard Edition 8.1.7
Oracle Oracle 9i Application Server Release 1 1.0.2 .2
Oracle listener 8.1.6
Oracle listener 8.0.6
Oracle Label Security 9.0.1
+ Oracle Oracle9i Standard Edition 9.0.1
- Sun Solaris 8_sparc
- Sun Solaris 7.0
- Sun Solaris 2.6
Oracle Label Security 8.1.7
Oracle iStore 11i 11i.IBE.O
Oracle Files 9.0.3 .3.6
Oracle Files 9.0.3 .3.0
+ Oracle Collaboration Suite Release 1
Oracle Files 9.0.3 .2.0
+ Oracle Collaboration Suite Release 1
Oracle Files 9.0.3 .1.0
+ Oracle Collaboration Suite Release 1
Oracle Enterprise Manager Grid Control 10g 10.1 .0.2
Oracle Enterprise Manager Database Control 10g 10.1 .0.2
Oracle Enterprise Manager 9.0.1
Oracle Enterprise Manager 9.0 i
Oracle E-Business Suite 11i 11.8
Oracle E-Business Suite 11i 11.7
Oracle E-Business Suite 11i 11.6
Oracle E-Business Suite 11i 11.5.9
Oracle E-Business Suite 11i 11.5.8
Oracle E-Business Suite 11i 11.5.7
Oracle E-Business Suite 11i 11.5.6
Oracle E-Business Suite 11i 11.5.5
Oracle E-Business Suite 11i 11.5.4
Oracle E-Business Suite 11i 11.5.3
Oracle E-Business Suite 11i 11.5.2
Oracle E-Business Suite 11i 11.5.1
Oracle E-Business Suite 11i 11.5
Oracle E-Business Suite 11i 11.4
Oracle E-Business Suite 11i 11.3
Oracle E-Business Suite 11i 11.2
Oracle E-Business Suite 11i 11.1
Oracle E-Business Suite 11.0
Oracle E-Business Suite 10.7
Oracle Configurator 11.0 i
Oracle Collaboration Suite Release 1
Oracle Applications 11.0
Oracle Applications 10.7
Oracle Application Server Web Cache 10g 9.0.4 .0
+ Oracle Oracle10g Application Server 9.0.4 .0
Oracle Application Server 10g 9.0.4 .1
Oracle Application Server 10g 9.0.4
Not Vulnerable:

Discussion

Oracle Multiple Unspecified Vulnerabilities

Reportedly, multiple unspecified Oracle products contain multiple unspecified vulnerabilities.

The reported vulnerabilities include SQL-injection issues, buffer-overflow issues, and others.

There have also been reports that issues covered in this BID and resolved in the referenced Oracle patch include trigger-abuse issues, character-set-conversion bugs, and denial-of-service vulnerabilities. More information is pending.

Note that a number of unsupported versions of affected products may also potentially be vulnerable.

Exploit / POC

Oracle Multiple Unspecified Vulnerabilities

Private exploits reportedly exist for many of these vulnerabilities.

The following exploit demonstrates CVE-2004-1364, the directory-traversal vulnerability in 'extproc':

Solution / Fix

Oracle Multiple Unspecified Vulnerabilities

Solution:
Oracle has released an alert (#68) and a patch to address these issues.

NOTE: A message from David Litchfield <[email protected]> states that some of the vulnerabilities in alert #68 may not have been successfully fixed by Oracle. Users of affected packages should refer to the referenced message and contact their vendor for further information on the status of fixes.

References

Oracle Multiple Unspecified Vulnerabilities

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report