Vulnerability record · CVE-2001-0499 · published 21 July 2001
CVE-2001-0499: Oracle 8i TNS Listener buffer overflow via command arguments
Oracle · Oracle8i
The Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier contains a buffer overflow reachable through long arguments to the STATUS, PING, SERVICES, TRC_FILE, SAVE_CONFIG, and RELOAD commands. A remote, unauthenticated attacker can trigger it over the network, and the flaw is severe because it can yield full control of the listener process.
Description
Buffer overflow in Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier allows remote attackers to gain privileges via a long argument to the commands (1) STATUS, (2) PING, (3) SERVICES, (4) TRC_FILE, (5) SAVE_CONFIG, or (6) RELOAD.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score of 10 with network reachability, no authentication, and complete confidentiality, integrity, and availability impact, plus very high EPSS, makes this a top-priority exposure despite the absence of KEV listing.
What it is
The Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier contains a buffer overflow reachable through long arguments to the STATUS, PING, SERVICES, TRC_FILE, SAVE_CONFIG, and RELOAD commands. A remote, unauthenticated attacker can trigger it over the network, and the flaw is severe because it can yield full control of the listener process.
Impact
An attacker gains the privileges of the TNS Listener process, which on Oracle installations typically runs with high system rights, enabling arbitrary code execution and potential full compromise of the database host.
Attack surface
Reachable over the network via the TNS Listener service; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. The description does not specify the default port or whether the listener must be exposed, so exposure depends on deployment.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is very high (0.852 probability, 99.7th percentile), indicating substantial observed exploitation likelihood. Reference tags are limited to US Government Resource and generic advisory links, with no public exploit tag supplied.
What to do
- Apply the Oracle patch or upgrade past 8i 8.1.7; this is the only complete fix.
- Restrict network access to the TNS Listener port with firewall rules and allow only trusted hosts.
- Disable or remove the listener's administrative commands where they are not needed, and run the listener under a least-privilege account.
- Monitor Oracle security advisories and CERT/CC guidance for interim workarounds if patching is delayed.
Detection
- Inspect TNS Listener logs for unusually long arguments or malformed commands such as STATUS, PING, SERVICES, TRC_FILE, SAVE_CONFIG, and RELOAD.
- Alert on listener process crashes, restarts, or unexpected child processes.
- Monitor network traffic to the listener port for oversized or anomalous command payloads.
- Correlate host process creation events from the listener with unexpected binaries or shell activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2001-0499 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2001-0499), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.