vendor:
Oracle10g
by:
Joxean Koret
7.5
CVSS
HIGH
Privilege Escalation
CWE
Product Name: Oracle10g
Affected Version From: Oracle10g R1 and R2 versions prior to CPU Oct 2006
Affected Version To: Oracle10g R1 and R2 versions prior to CPU Oct 2006
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
Oracle10g R1 and R2 Privilege Escalation Exploit
This exploit targets Oracle10g R1 and R2 versions prior to CPU Oct 2006. It allows an attacker to escalate their privileges by creating a session and a procedure. The exploit uses a function called F1, which is granted DBA privileges to the user 'TEST'. The exploit then executes the function and commits the changes. Finally, it retrieves user role privileges using the user_role_privs table. The exploit was developed by Joxean Koret.
Mitigation:
Apply the latest CPU patch from Oracle to fix this vulnerability.