VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 19 hours ago

CVE-2004-1364

8.5 High Protected by RASP

Description

Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries outside of the $ORACLE_HOME\bin directory.

CWE-22 · Path traversal

Exploitation Status

Working exploit published

A reviewed exploit catalogue carries this CVE. Somebody has published code a stranger can run.

CVSS E:P

  • CISA KEV not listed
  • CISA Vulnrichment no assessment published
  • Indexed PoC 2 indexed Published artifacts you can open, in Exploit-DB; first seen 2004-08-04.
  • EPSS 14% chance in 30 days A model prediction, not an observation. Higher than 96% of all scored CVEs.
IndexArtifactStarsFirst seen
Exploit-DB Oracle 9i/10g - 'extproc' Local/Remote Command Execution 2006-12-19
Exploit-DB Oracle 9i - Multiple Vulnerabilities 2004-08-04

Waratek Defense Posture

Protected by RASP

A Waratek agent blocks this today.

Applicable rule: Promoted to MITIGATED-BY-RASP (security rule): this CVE's weakness (CWE-22: Path Traversal) can be mitigated by an ARMR path-traversal security rule that blocks this class of attack at the JVM level, without requiring a CVE-specific patch.

  • Protection full a general security rule for the vulnerability class
  • Action available security rule
  • Review automated inferred
  • Record active
Decided by secure-rule-match : A vulnerability class already blocked by an ARMR security rule
Finding Promoted to MITIGATED-BY-RASP (security rule): this CVE's weakness (CWE-22: Path Traversal) can be mitigated by an ARMR path-traversal security rule that blocks this class of attack at the JVM level, without requiring a CVE-specific patch.

CVSS

8.5 v2.0 AV:N/AC:M/Au:S/C:C/I:C/A:C 1 metric

VRT selects the newest version's highest entry and publishes it as cvssScore, newest rather than largest because scores are not comparable across versions, and highest rather than first because the first entry is frequently a CNA placeholder scoring 0.0 over NVD's own analysis.

VersionScoreBandVectorAssignerType
CVSS 2.0 8.5 no band published AV:N/AC:M/Au:S/C:C/I:C/A:C NVD Primary published

Affected Software & Releases

🖥️ Product CPEs & Version Ranges

9 product(s) over 87 version claims (uncapped)
SourceVendorProductSchemeAffected Versions
nvd oracle application server generic any version · 9.0.2 · 9.0.2.0.0 · 9.0.2.0.1 · 9.0.2.1 · 9.0.2.2 · 9.0.2.3 · 9.0.3 · 9.0.3.1 · 9.0.4 · 9.0.4.0 · 9.0.4.1
nvd oracle collaboration suite generic release_1
nvd oracle e-business suite generic 11.5.1 · 11.5.2 · 11.5.3 · 11.5.4 · 11.5.5 · 11.5.6 · 11.5.7 · 11.5.8 · 11.5.9
nvd oracle enterprise manager generic 9 · 9.0.1
nvd oracle enterprise manager database control generic 10.1.2
nvd oracle enterprise manager grid control generic 10.1.0.2
nvd oracle oracle10g generic enterprise_9.0.4_.0 · personal_9.0.4_.0 · standard_9.0.4_.0 · enterprise_10.1.0.2 · personal_10.1_.0.2 · standard_10.1_.0.2
nvd oracle oracle8i generic enterprise_8.0.5_.0.0 · standard_8.0.6 · enterprise_8.0.6_.0.0 · enterprise_8.0.6_.0.1 · standard_8.0.6_.3 · standard_8.1.5 · enterprise_8.1.5_.0.0 · enterprise_8.1.5_.0.2 · enterprise_8.1.5_.1.0 · standard_8.1.6 · enterprise_8.1.6_.0.0 · enterprise_8.1.6_.1.0 · standard_8.1.7 · enterprise_8.1.7_.0.0 · standard_8.1.7_.0.0 · standard_8.1.7_.1 · enterprise_8.1.7_.1.0 · enterprise_8.1.7_.4 · standard_8.1.7_.4
nvd oracle oracle9i generic enterprise_8.1.7 · personal_8.1.7 · standard_8.1.7 · standard_9.0 · enterprise_9.0.1 · personal_9.0.1 · standard_9.0.1 · standard_9.0.1.2 · standard_9.0.1.3 · enterprise_9.0.1.4 · personal_9.0.1.4 · standard_9.0.1.4 · enterprise_9.0.1.5 · personal_9.0.1.5 · standard_9.0.1.5 · standard_9.0.2 · personal_9.2 · standard_9.2 · enterprise_9.2.0 · client_9.2.0.1 · enterprise_9.2.0.1 · personal_9.2.0.1 · standard_9.2.0.1 · client_9.2.0.2 · enterprise_9.2.0.2 · personal_9.2.0.2 · standard_9.2.0.2 · enterprise_9.2.0.3 · personal_9.2.0.3 · standard_9.2.0.3 · enterprise_9.2.0.4 · personal_9.2.0.4 · standard_9.2.0.4 · enterprise_9.2.0.5 · personal_9.2.0.5 · standard_9.2.0.5

References

URLTags
http://marc.info/?l=bugtraq&m=110382406002365&w=2
http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1
http://www.0xdeadbeef.info/exploits/raptor_oraextproc.sql
http://www.kb.cert.org/vuls/id/316206 US Government Resource
http://www.ngssoftware.com/advisories/oracle23122004B.txt Patch, Vendor Advisory
http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf Patch, Vendor Advisory
http://www.securityfocus.com/archive/1/454861/100/0/threaded
http://www.securityfocus.com/bid/10871 Patch
http://www.us-cert.gov/cas/techalerts/TA04-245A.html Patch, Third Party Advisory, US Government Resource
https://exchange.xforce.ibmcloud.com/vulnerabilities/18658

Timeline

Published 2004-08-04 Last modified 2026-06-16
Published2004-08-04By the CVE Program.
NVD record modified2026-06-16NVD's own last-modified date for this record.