Vulnerability record · CVE-2009-1979 · published 22 October 2009
CVE-2009-1979: Oracle Database Network Authentication component remote code execution risk
Oracle · Database Server
An unspecified flaw in the Network Authentication component of Oracle Database 10.1.0.5 and 10.2.0.4 lets remote attackers affect confidentiality, integrity and availability over the network without authentication. Oracle's October 2009 CPU entry is vague, but an independent researcher claims it stems from improper validation of the AUTH_SESSKEY parameter length, potentially allowing arbitrary code execution.
Description
Unspecified vulnerability in the Network Authentication component in Oracle Database 10.1.0.5 and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2009 CPU. Oracle has not commented on claims from an independent researcher that this is related to improper validation of the AUTH_SESSKEY parameter length that leads to arbitrary code execution.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 10.0 with no authentication or interaction required and a very high EPSS score make this a top remediation priority despite the thin vendor description.
What it is
An unspecified flaw in the Network Authentication component of Oracle Database 10.1.0.5 and 10.2.0.4 lets remote attackers affect confidentiality, integrity and availability over the network without authentication. Oracle's October 2009 CPU entry is vague, but an independent researcher claims it stems from improper validation of the AUTH_SESSKEY parameter length, potentially allowing arbitrary code execution.
Impact
A successful attack can fully compromise confidentiality, integrity and availability of the database, and if the AUTH_SESSKEY claim holds, may allow arbitrary code execution on the database host.
Attack surface
Reachable over the network via the database's authentication listener path (AV:N/AC:L/Au:N), requiring no authentication and no user interaction; the exact protocol vector is not specified in the record.
Exploitation
Not listed in CISA KEV and no reference carries an exploit tag, but EPSS is very high (0.764, 99.5th percentile), indicating strong predicted exploitation likelihood.
What to do
- Apply the Oracle October 2009 Critical Patch Update or a later patch level for Database 10.1.0.5 and 10.2.0.4.
- Restrict network access to the database listener and authentication ports to trusted hosts only.
- Disable or block unused authentication methods and enforce strong listener-level access controls.
- Monitor Oracle security advisories for updated guidance on the AUTH_SESSKEY validation claim.
Detection
- Alert on unusually long or malformed AUTH_SESSKEY values in database authentication traffic.
- Monitor listener logs for repeated failed authentication attempts from unexpected source addresses.
- Baseline normal authentication traffic volume and flag deviations from external or untrusted networks.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-1979 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-1979), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.