vendor:
Database Server
by:
SecurityFocus
7.2
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: Database Server
Affected Version From: Oracle Database 10.1
Affected Version To: Oracle Database 11g
Patch Exists: NO
Related CWE: N/A
CPE: oracle:database_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2008
Oracle Database Server Privilege Escalation Vulnerability
Oracle Database Server is prone to a privilege-escalation issue related to the 'CREATE ANY DIRECTORY' user privilege. Attackers may exploit this issue to gain full SYSDBA privileges on the vulnerable database server.
Mitigation:
Users should remove the 'CREATE ANY DIRECTORY' privilege from all users.