Vulnerability Name: | CCN-20154 | ||||||
Published: | 2005-04-18 | ||||||
Updated: | 2005-04-18 | ||||||
Summary: | Oracle Database Server is vulnerable to a denial of service attack, caused by a vulnerability in the ORDImage and ORDDoc objects. By sending a specially-crafted file to the ORDImage object or the ORDDoc object, a remote attacker with PUBLIC rights could cause the server to consume 100% of the CPU resources. A remote attacker could exploit this vulnerability to cause a denial of service. The server must be restarted to regain normal functionality. | ||||||
CVSS v3 Severity: | 5.7 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H)
| ||||||
CVSS v2 Severity: | 6.8 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:C) 5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:C/E:U/RL:OF/RC:C)
| ||||||
Vulnerability Consequences: | Denial of Service | ||||||
References: | Source: CCN Type: SHATTER Team Security Alert April 18, 2005 Denial of Service in Oracle interMedia Source: CCN Type: Oracle Database Server Web page Oracle Database Source: CCN Type: Oracle Critical Patch Update Advisory April 2005 Oracle Critical Patch Update Advisory - April 2005 Source: CCN Type: BID-13139 Oracle Multiple Vulnerabilities Source: CCN Type: BID-13239 Oracle Database Server InterMedia Denial of Service Vulnerability Source: XF Type: UNKNOWN oracle-database-ordimage-orddoc-dos(20154) | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |