Back

CVE-2004-1364

Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries outside of the $ORACLE_HOME\bin directory.

Published: Aug 4, 2004 Modified: Jun 16, 2026
CWE-22

CVSS Metrics

Affected Products (87)

Vendor Product Version
oracle application_server *
oracle application_server 9.0.2
oracle application_server 9.0.2.0.0
oracle application_server 9.0.2.0.1
oracle application_server 9.0.2.1
oracle application_server 9.0.2.2
oracle application_server 9.0.2.3
oracle application_server 9.0.3
oracle application_server 9.0.3.1
oracle application_server 9.0.4
oracle application_server 9.0.4.0
oracle application_server 9.0.4.1
oracle collaboration_suite release_1
oracle e-business_suite 11.5.1
oracle e-business_suite 11.5.2
oracle e-business_suite 11.5.3
oracle e-business_suite 11.5.4
oracle e-business_suite 11.5.5
oracle e-business_suite 11.5.6
oracle e-business_suite 11.5.7

…and 67 more

GitHub Security Advisory GHSA-rx5m-vvp9-4xw5

Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to...

Risk Scores

CVSS Score 8.5 / 10
EPSS Score 13.78%

Top 4% most likely to be exploited

Threat Score 38.1 / 100

Data Sources

NVD EPSS GitHub