. Oracle9i Release 2
. Oracle9i Release 1
. Oracle8i (8.1.x - all releases )
Oracle provides a method of calling functions outside of the database by creating external procedure servers. This feature extends Oracle's functionality and is very useful. However, if access to send commands to these external procedure servers is not properly restricted, anonymous users can gain control of the operating system. A malicious attacker can write an exploit to have an access to the underlying operating system calls giving unauthorized administrative access to the Oracle Database Server.
Impact
This flaw in an organization's database server could allow an attacker to execute code against the system. The main concern with this type of an attack is that a company insider could gain a higher level of privilege on the server.