CVE-1999-0888

Oracle Intelligent Agent - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-1999-0888. PoCs published by Gilles PARC, Brock Tellier.

AI-analyzed exploit summary This exploit leverages a vulnerability in Oracle Intelligent Agent's dbsnmp program, which trusts the ORACLE_HOME environment variable without verification. It manipulates the environment to execute arbitrary commands as root via a crafted TCL script and creates world-writable files.

Description

dbsnmp in Oracle Intelligent Agent allows local users to gain privileges by setting the ORACLE_HOME environmental variable, which dbsnmp uses to find the nmiconf.tcl script.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Gilles PARC · clocalmultiple
https://www.exploit-db.com/exploits/19461

This exploit leverages a vulnerability in Oracle Intelligent Agent's dbsnmp program, which trusts the ORACLE_HOME environment variable without verification. It manipulates the environment to execute arbitrary commands as root via a crafted TCL script and creates world-writable files.

Classification
Working Poc 90%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Oracle Intelligent Agent (dbsnmp) in Oracle 8.0.5
No auth needed
Prerequisites: Local access to the system · Presence of Oracle Intelligent Agent with vulnerable dbsnmp binary · Ability to manipulate environment variables
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Brock Tellier · bashlocalmultiple
https://www.exploit-db.com/exploits/19460

This exploit leverages a vulnerability in Oracle Intelligent Agent (dbsnmp) where the ORACLE_HOME environment variable is trusted without verification. It creates a symlink to /.rhosts and exploits the setuid root binary to create a world-writable file, enabling arbitrary command execution as root via rsh.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: Oracle Intelligent Agent (dbsnmp) in Oracle 8.1.5
No auth needed
Prerequisites: Oracle 8.1.5 installed with vulnerable dbsnmp binary · /.rhosts file must not exist · Local access to the system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/585

Scores

EPSS 0.0107
EPSS Percentile 60.6%

Details

Status published
Products (7)
oracle/database_server 7.3.3
oracle/database_server 7.3.4
oracle/oracle8i 8.0.3
oracle/oracle8i 8.0.4
oracle/oracle8i 8.0.5
oracle/oracle8i 8.0.5.1
oracle/oracle8i 8.1.5
Published Aug 16, 1999
Tracked Since Feb 18, 2026