vendor:
Oracle Database
by:
Andrea "bunker" Purificato
5.5
CVSS
MEDIUM
Grant or revoke dba permission to unprivileged user
CWE
Product Name: Oracle Database
Affected Version From: Oracle Database 9i/10g
Affected Version To: Oracle Database 9i/10g
Patch Exists:
Related CWE:
CPE:
Platforms Tested:
2007
Remote Oracle DBMS_CDC_SUBSCRIBE.ACTIVATE_SUBSCRIPTION exploit (9i/10g)
This exploit allows an attacker to grant or revoke dba permission to an unprivileged user in Oracle DBMS_CDC_SUBSCRIBE.ACTIVATE_SUBSCRIPTION. It has been tested on Oracle Database 10g Enterprise Edition Release 10.1.0.3.0.
Mitigation:
Ensure proper access control and permissions are in place to prevent unauthorized granting or revoking of dba permission.