vendor:
Oracle Database
by:
Andrea "bunker" Purificato
5.5
CVSS
MEDIUM
Grant or revoke dba permission to unprivileged user
269
CWE
Product Name: Oracle Database
Affected Version From: 10.1.0.5.0
Affected Version To: 10.1.0.5.0
Patch Exists: YES
Related CWE:
CPE: a:oracle:database:10.1.0.5.0
Platforms Tested:
2007
Oracle SYS.LT.FINDRICSET exploit
This exploit allows an attacker to grant or revoke dba permission to an unprivileged user in Oracle databases. It has been tested on Oracle Database 10g Enterprise Edition Release 10.1.0.5.0. The vulnerability was fixed with CPU Oct. 2007. The exploit requires Oracle InstantClient (basic + sdk) for DBD::Oracle.
Mitigation:
Apply the relevant security patches from Oracle to fix this vulnerability.