The default installation for the Oracle listener program 7.3.4, 8.0.6, and 8.1.6 allows an attacker to cause logging information to be appended to arbitrary files and execute commands via the SET TRC…
Info
Summary
The default installation for the Oracle listener program 7.3.4, 8.0.6, and 8.1.6 allows an attacker to cause logging information to be appended to arbitrary files and execute commands via the SET TRC_FILE or SET LOG_FILE commands.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- http://otn.oracle.com/deploy/security/pdf/listener_alert.pdf Patch
- http://xforce.iss.net/alerts/advise66.php Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5380
- http://otn.oracle.com/deploy/security/pdf/listener_alert.pdf Patch
- http://xforce.iss.net/alerts/advise66.php Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5380
Timeline
- nvd_ingest NVD