{ "id": "CVE-2005-0298", "sourceIdentifier": "cve@mitre.org", "published": "2005-05-02T04:00:00.000", "lastModified": "2024-11-20T23:54:50.073", "vulnStatus": "Modified", "cveTags": [], "descriptions": [ { "lang": "en", "value": "The DIRECTORY objects in Oracle 8i through Oracle 10g contain the location of a specific operating system directory, which allows users with read privileges to a DIRECTORY object to obtain sensitive information." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N", "baseScore": 5.0, "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "availabilityImpact": "NONE" }, "baseSeverity": "MEDIUM", "exploitabilityScore": 10.0, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "NVD-CWE-Other" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:oracle:database_server:8.0.6:*:*:*:*:*:*:*", "matchCriteriaId": "9C84852A-1153-46A7-9B82-D05F4A6043D9" }, { "vulnerable": true, "criteria": "cpe:2.3:a:oracle:database_server:8.0.6.3:*:*:*:*:*:*:*", "matchCriteriaId": "FACC77BE-277F-47F9-B50A-2E9CF5D4A965" }, { "vulnerable": true, "criteria": "cpe:2.3:a:oracle:database_server:8.1.7.4:*:*:*:*:*:*:*", "matchCriteriaId": "B559C62F-88A7-42D3-9629-9F5CAD43F8B6" }, { "vulnerable": true, "criteria": "cpe:2.3:a:oracle:database_server:9.0.1.4:*:*:*:*:*:*:*", "matchCriteriaId": "2109201B-89F7-4FF2-BFD1-2B220E3146FD" }, { "vulnerable": true, "criteria": "cpe:2.3:a:oracle:database_server:9.0.1.5:*:*:*:*:*:*:*", "matchCriteriaId": "B6C67572-800C-4214-AD12-E9017A9A5BAA" }, { "vulnerable": true, "criteria": "cpe:2.3:a:oracle:database_server:9.0.4:*:*:*:*:*:*:*", "matchCriteriaId": "E108197C-DCA8-4624-9FEF-621BFB299662" }, { "vulnerable": true, "criteria": "cpe:2.3:a:oracle:database_server:9.2.0.4:*:*:*:*:*:*:*", "matchCriteriaId": "B4C63EC8-73D7-46AE-81E7-04DF212BC8B5" }, { "vulnerable": true, "criteria": "cpe:2.3:a:oracle:database_server:9.2.0.5:*:*:*:*:*:*:*", "matchCriteriaId": "47CC3066-82BA-41AB-B6C8-D2E7D7AE7D6F" }, { "vulnerable": true, "criteria": "cpe:2.3:a:oracle:database_server:9.2.0.6:*:*:*:*:*:*:*", "matchCriteriaId": "07F11F24-415A-4E36-9D03-5B7594356183" }, { "vulnerable": true, "criteria": "cpe:2.3:a:oracle:database_server:10.1.0.2:*:*:*:*:*:*:*", "matchCriteriaId": "553BAC35-0A37-40C2-A150-F34D59D097F4" }, { "vulnerable": true, "criteria": "cpe:2.3:a:oracle:database_server:10.1.0.3:*:*:*:*:*:*:*", "matchCriteriaId": "C4019F72-9031-4CA6-B39A-AFC203D9D464" }, { "vulnerable": true, "criteria": "cpe:2.3:a:oracle:database_server:10.1.0.3.1:*:*:*:*:*:*:*", "matchCriteriaId": "F54497B9-D154-4751-9871-BF2D650F76AF" } ] } ] } ], "references": [ { "url": "http://marc.info/?l=bugtraq&m=110608912525883&w=2", "source": "cve@mitre.org" }, { "url": "http://www.oracle.com/technology/deploy/security/pdf/cpu-jan-2005_advisory.pdf", "source": "cve@mitre.org", "tags": [ "Patch" ] }, { "url": "http://www.petefinnigan.com/directory_traversal.pdf", "source": "cve@mitre.org", "tags": [ "Patch", "Vendor Advisory" ] }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/18947", "source": "cve@mitre.org" }, { "url": "http://marc.info/?l=bugtraq&m=110608912525883&w=2", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://www.oracle.com/technology/deploy/security/pdf/cpu-jan-2005_advisory.pdf", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Patch" ] }, { "url": "http://www.petefinnigan.com/directory_traversal.pdf", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Patch", "Vendor Advisory" ] }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/18947", "source": "af854a3a-2127-422b-91ae-364da2661108" } ] }