vendor:
Oracle Database
by:
sid[at]notsosecure.com
7.5
CVSS
HIGH
Remote Privilege Escalation
CWE
Product Name: Oracle Database
Affected Version From: Oracle Database 11gR1
Affected Version To: Oracle Database 11gR2
Patch Exists: NO
Related CWE:
CPE: oracle:database
Platforms Tested: Windows
2010
DBMS_JVM_EXP_PERMS 11g R1/R2 OS Code Execution
This module exploits a flaw (0 day) in DBMS_JVM_EXP_PERMS package that allows any user with create session privilege to grant themselves java IO privileges. Works on 11g R1 and R2 (Windows only).
Mitigation:
Apply the necessary patches and updates from Oracle.