cbcvebase.
CVE-2007-4517
published 2007-11-08

CVE-2007-4517: Buffer overflow in the XDB.XDB_PITRIG_PKG.PITRIG_DROPMETADATA procedure in Oracle 10g R2 allows remote authenticated users to execute arbitrary code via a long…

PriorityP335medium6CVSS 2.0
AVNACMAuSCPIPAP
EXPLOIT
EPSS
5.38%
91.8th percentile
Buffer overflow in the XDB.XDB_PITRIG_PKG.PITRIG_DROPMETADATA procedure in Oracle 10g R2 allows remote authenticated users to execute arbitrary code via a long (1) OWNER or (2) NAME argument.

Affected

1 ranges
VendorProductVersion rangeFixed in
oracledatabase_server

Detection & IOCsextracted from sources · hover to see the quote

otherusername: GreenSQL, password: GreenSQL (created by payload on OS)
bytes
80EBB080C7FAFFE3
  • Detect unexpected stopping of the OracleServiceXE Windows service, which is a symptom of successful exploitation.
  • Look for the JMP2SC opcode sequence 80 EB B0 80 C7 FA FF E3 in Oracle network traffic or PL/SQL audit captures; this is the exploit's trampoline stub (sub bl,0xb0 / add bh,0xfa / jmp ebx).
  • ·The exploit requires a remote authenticated Oracle session; unauthenticated exploitation is not possible with this PoC.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.