vendor:
Oracle Database
by:
Andrea "bunker" Purificato
7.5
CVSS
HIGH
Grant or revoke dba permission to unprivileged user
CWE
Product Name: Oracle Database
Affected Version From: Oracle DBMS_METADAT.GET_DDL (9i/10g)
Affected Version To: Oracle DBMS_METADAT.GET_DDL (9i/10g)
Patch Exists: No
Related CWE:
CPE:
Platforms Tested:
2007
Remote Oracle DBMS_METADAT.GET_DDL exploit
This exploit allows an attacker to grant or revoke dba permission to an unprivileged user in Oracle DBMS_METADAT.GET_DDL (9i/10g) versions. The attacker needs to have Oracle InstantClient (basic + sdk) installed for DBD::Oracle.
Mitigation:
Unknown