CVE-2008-2613
published 2008-07-15CVE-2008-2613: Unspecified vulnerability in the Database Scheduler component in Oracle Database 10.2.0.4 and 11.1.0.6 has unknown impact and local attack vectors. NOTE: the…
PriorityP425medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
1.34%
68.4th percentile
Unspecified vulnerability in the Database Scheduler component in Oracle Database 10.2.0.4 and 11.1.0.6 has unknown impact and local attack vectors. NOTE: the previous information was obtained from the Oracle July 2008 CPU. Oracle has not commented on reliable researcher claims that this is an untrusted search path issue that allows local users to gain privileges via a malicious (1) libclntsh.so or (2) libnnz10.so library.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | database_server | — | — |
| oracle | database_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
CWE
External Influence of Sphere Definition
mitre_cwe·CVSS 6.5
[MEDIUM] CWE-673 External Influence of Sphere Definition
CWE-673: External Influence of Sphere Definition
The product does not prevent the definition of control spheres from external actors.
Typically, a product defines its control sphere within the code itself, or through configuration by the product's administrator. In some cases, an external party can change the definition of the control sphere. This is typically a resultant weakness.
Modes of Introduction:
Phase: Architecture and Design
Phase: Implementation
Note: REALIZATION: This weakness is caused during implementation of an architectural security tactic.
Common Consequences:
Scope: Other. Impact: Other.
Examples:
Consider a blog publishing tool, which might have three explicit control spheres: the creation of articles, only accessible to a "publisher;" commenting on articles, only a
CWE
Untrusted Search Path
mitre_cwe
CWE-426 Untrusted Search Path
CWE-426: Untrusted Search Path
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
This might allow attackers to execute their own programs, access unauthorized data files, or modify configuration in unexpected ways. If the product uses a search path to locate critical resources such as programs, then an attacker could modify that search path to point to a malicious program, which the targeted product would then execute. The problem extends to any type of critical resource that the product trusts. Some of the most common variants of untrusted search path are: In various UNIX and Linux-based systems, the PATH environment variable may be consulted to locate executable programs, and
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00727143http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=727http://secunia.com/advisories/31087http://secunia.com/advisories/31113http://www.oracle.com/technetwork/topics/security/cpujul2008-090335.htmlhttp://www.securityfocus.com/archive/1/494544/100/0/threadedhttp://www.securitytracker.com/id?1020499http://www.vupen.com/english/advisories/2008/2109/referenceshttp://www.vupen.com/english/advisories/2008/2115http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00727143http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=727http://secunia.com/advisories/31087http://secunia.com/advisories/31113http://www.oracle.com/technetwork/topics/security/cpujul2008-090335.htmlhttp://www.securityfocus.com/archive/1/494544/100/0/threadedhttp://www.securitytracker.com/id?1020499http://www.vupen.com/english/advisories/2008/2109/referenceshttp://www.vupen.com/english/advisories/2008/2115
2008-07-15
Published