vendor:
Oracle Database
by:
Andrea 'bunker' Purificato
8.8
CVSS
HIGH
Oracle SYS.LT.COMPRESSWORKSPACETREE exploit
264
CWE
Product Name: Oracle Database
Affected Version From: 9iR2/10gR1
Affected Version To: 11gR1
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
sys-lt-compressworkspacetreeV2.sql exploit
This exploit grants DBA permission to an unprivileged user by using the Evil cursor technique. It creates an evil cursor and then uses the SYS.LT.CREATEWORKSPACE and SYS.LT.COMPRESSWORKSPACETREE functions to execute the malicious code.
Mitigation:
Restrict access to the SYS.LT.CREATEWORKSPACE and SYS.LT.COMPRESSWORKSPACETREE functions.