cbcvebase.
CVE-2004-1707
published 2004-07-30

CVE-2004-1707: The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default path to find and execute library files…

PriorityP431high7.2CVSS 2.0
AVLACLAuNCCICAC
EXPLOIT
EPSS
2.57%
83.4th percentile
The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default path to find and execute library files while operating at raised privileges, which allows certain Oracle user accounts to gain root privileges via a modified libclntsh.so.9.0.

Affected

69 ranges· showing 25
VendorProductVersion rangeFixed in
oracleapplication_server
oracleapplication_server
oracleapplication_server
oracleapplication_server
oracleapplication_server
oracleapplication_server
oracleapplication_server
oracleapplication_server
oracleapplication_server
oracleapplication_server
oracleapplication_server
oracleapplication_server
oracleapplication_server_portal
oracleapplication_server_portal
oracleapplication_server_portal
oracleapplication_server_portal
oracledatabase_server_lite
oracledatabase_server_lite
oracledatabase_server_lite
oracleoracle8i
oracleoracle8i
oracleoracle8i
oracleoracle8i
oracleoracle8i
oracleoracle8i
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.