CVE-2000-0818 describes a critical vulnerability in the default installation of Oracle listener programs (versions 7.3.4, 8.0.6, and 8.1.6). An unauthenticated attacker can exploit this flaw by using SET TRC_FILE or SET LOG_FILE commands to append logging information to arbitrary files and execute commands. This vulnerability carries a CVSS score of 10.0, indicating a severe risk with network-based attacks, low complexity, and complete compromise of confidentiality, integrity, and availability. While the vulnerability is old and has no known active exploits, public exploit code, or community discussion, its high severity warrants attention for systems still running these outdated Oracle versions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.3.4CPE matchmatch criteria | cpe:2.3:a:oracle:listener:7.3.4:*:*:*:*:*:*:* | ||
8.0.6CPE matchmatch criteria | cpe:2.3:a:oracle:listener:8.0.6:*:*:*:*:*:*:* | ||
8.1.6CPE matchmatch criteria | cpe:2.3:a:oracle:listener:8.1.6:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.