4.6
CVSSv2

CVE-1999-0711

Published: 29/04/1999 Updated: 18/10/2016
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The oratclsh interpreter in Oracle 8.x Intelligent Agent for Unix allows local users to execute Tcl commands as root.

Vulnerable Product Search on Vulmon Subscribe to Product

oracle oracle8i 8.1.5

oracle oracle8i 8.0.5

oracle oracle8i 8.0.5.1

oracle oracle8i 8.0.3

oracle oracle8i 8.0.4

Exploits

source: wwwsecurityfocuscom/bid/159/info Oracle8 is an enterprise level database As part of the Internet Agent option installation process it installs the file $ORACLE_HOME/bin/oratclsh as suid root oratclsh is a TCL application that provides full access to TCL oratclsh gives anyone the ability to execute arbitrary TCL commands as root ...