CVE-2008-2595

Oracle Internet Directory 9.0.4.3, 10.1.2.3, 10.1.4.2 - Denial of Service via Malformed LDAP Request

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-2595. PoCs published by Joxean Koret.

AI-analyzed exploit summary This exploit targets a pre-authentication Denial of Service (DoS) vulnerability in Oracle Internet Directory 10.1.4 by sending a malformed packet to crash the service. It includes a health check to verify the success of the attack.

Description

Unspecified vulnerability in the Oracle Internet Directory component in Oracle Application Server 9.0.4.3, 10.1.2.3, and 10.1.4.2 has unknown impact and remote attack vectors. NOTE: the previous information was obtained from the Oracle July 2008 CPU. Oracle has not commented on reliable researcher claims that this issue is a denial of service (crash) via a malformed LDAP request that triggers a NULL pointer dereference.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Joxean Koret · pythondosmultiple
https://www.exploit-db.com/exploits/6101

This exploit targets a pre-authentication Denial of Service (DoS) vulnerability in Oracle Internet Directory 10.1.4 by sending a malformed packet to crash the service. It includes a health check to verify the success of the attack.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Oracle Internet Directory 10.1.4
No auth needed
Prerequisites: Network access to the target LDAP service
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1020494
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2115
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2109/references
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6101
Third Party Advisory third-party-advisory x_refsource_idefense
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=725
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31087
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31113

Scores

EPSS 0.1134
EPSS Percentile 95.4%

Details

Status published
Products (3)
oracle/database_10g 10.1.2.3
oracle/database_10g 10.1.4.2
oracle/database_9i 9.0.4.3
Published Jul 15, 2008
Tracked Since Feb 18, 2026