The triggers in Oracle 9i and 10g allow local users to gain privileges by using a sequence of partially privileged actions: using CCBKAPPLROWTRIG or EXEC_CBK_FN_DML to add arbitrary functions to the SDO_CMT_DBK_FN_TABLE and SDO_CMT_CBK_DML_TABLE, then performing a DELETE on the SDO_TXN_IDX_INSERTS table, which causes the SDO_CMT_CBK_TRIG trigger to execute the user-supplied functions.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2005-01-06T05:00:00
Updated: 2024-08-08T00:46:12.320Z
Reserved: 2005-01-06T00:00:00
Link: CVE-2004-1338
Vulnrichment
No data.
NVD
Status : Modified
Published: 2004-12-23T05:00:00.000
Modified: 2024-11-20T23:50:38.393
Link: CVE-2004-1338
Redhat
No data.