CVE-2007-2108

Oracle Database <=10.2.0.2 Windows Privilege Escalation via NTLM SSPI

Title source: llm
STIX 2.1

Description

Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.2 on Windows allows remote attackers to have an unknown impact, aka DB01. NOTE: as of 20070424, Oracle has not disputed reliable claims that this issue occurs because the NTLM SSPI AcceptSecurityContext function grants privileges based on the username provided even though all users are authenticated as Guest, which allows remote attackers to gain privileges.

References (11)

Core 11
Core References
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA07-108A.html
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/809457
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/23532
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1017927
Third Party Advisory, VDB Entry vendor-advisory x_refsource_hp
http://www.securityfocus.com/archive/1/466329/100/200/threaded
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/1426
Various Sources x_refsource_misc
http://www.ngssoftware.com/papers/database-on-xp.pdf

Scores

EPSS 0.2150
EPSS Percentile 97.4%

Details

CWE
CWE-264
Status published
Products (5)
microsoft/windows
oracle/database_server 9.0.1.5
oracle/database_server 9.2.0.8
oracle/database_server 10.1.0.5
oracle/database_server 10.2.0.2
Published Apr 18, 2007
Tracked Since Feb 18, 2026