vendor:
Oracle Database
by:
Andrea Purificato
7.5
CVSS
HIGH
Remote Code Execution
94
CWE
Product Name: Oracle Database
Affected Version From: Oracle Database 9i
Affected Version To: Oracle Database 10g
Patch Exists: NO
Related CWE:
CPE: a:oracle:database
Platforms Tested:
2007
Remote Oracle DBMS_METADATA.GET_DDL exploit (9i/10g)
This exploit allows an attacker to grant or revoke dba permission to an unprivileged user in Oracle DBMS_METADATA.GET_DDL. It uses an 'evil cursor injection' technique and does not require 'create procedure' privilege. The exploit has been tested on Oracle Database 10g Enterprise Edition Release 10.1.0.3.0. The exploit script is provided in Perl.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of Oracle Database and apply necessary security patches.