Oracle Database Vault Privilege Escalation Vulnerability
BID:32393
Info
Oracle Database Vault Privilege Escalation Vulnerability
| Bugtraq ID: | 32393 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 20 2008 12:00AM |
| Updated: | Nov 21 2008 12:13AM |
| Credit: | Jakub Wartak |
| Vulnerable: |
Oracle Oracle10g Standard Edition 10.2 .3 Oracle Oracle10g Personal Edition 10.2 .3 Oracle Oracle10g Enterprise Edition 10.2 .3 |
| Not Vulnerable: | |
Discussion
Oracle Database Vault Privilege Escalation Vulnerability
Oracle Database Vault is prone to a privilege-escalation vulnerability.
An attacker with SYSDBA access to the Oracle user space can exploit this issue to bypass intended security measures and obtain potentially sensitive information.
Oracle Database 10.2.0.3 is affected; other versions may also be vulnerable.
Oracle Database Vault is prone to a privilege-escalation vulnerability.
An attacker with SYSDBA access to the Oracle user space can exploit this issue to bypass intended security measures and obtain potentially sensitive information.
Oracle Database 10.2.0.3 is affected; other versions may also be vulnerable.
Exploit / POC
Oracle Database Vault Privilege Escalation Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Oracle Database Vault Privilege Escalation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Oracle Database Vault Privilege Escalation Vulnerability
References:
References:
- Oracle Database Vault, not so 0-day anymore, privilege escalation using ptrace(2 (Jakub Wartak)
- Oracle Homepage (Oracle)