CVE-2013-3751
Oracle Database Server SQL QName Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Unspecified vulnerability in the XML Parser component in Oracle Database Server 11.2.0.2, 11.2.0.3, and 12.1.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
Vulnerabilidad no especificada en el componente XML Parser en Oracle Database Server v11.2.0.2 y v11.2.0.3 permite a usuarios remotos autenticados afectar la confidencialidad, integridad y disponibilidad mediante vectores desconocidos.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Database. Authentication is not required to exploit this vulnerability.
The specific flaw exists in the LpxFSMDom function. This function is responsible for parsing SQL commands through XML. A specially crafted QName used in a SQL SELECT command can result in a stack overflow. An attacker can leverage this vulnerability to execute code under the context of the process.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-06-03 CVE Reserved
- 2013-07-17 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://osvdb.org/95264 | Vdb Entry | |
http://seclists.org/fulldisclosure/2014/Dec/23 | Mailing List | |
http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html | X_refsource_confirm | |
http://www.securityfocus.com/archive/1/534161/100/0/threaded | Mailing List | |
http://www.securitytracker.com/id/1028789 | Vdb Entry | |
http://www.vmware.com/security/advisories/VMSA-2014-0012.html | X_refsource_confirm | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/85650 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oracle Search vendor "Oracle" | Database Server Search vendor "Oracle" for product "Database Server" | 11.2.0.2 Search vendor "Oracle" for product "Database Server" and version "11.2.0.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Database Server Search vendor "Oracle" for product "Database Server" | 11.2.0.3 Search vendor "Oracle" for product "Database Server" and version "11.2.0.3" | - |
Affected
|