PT-2005-1376 · Oracle · Oracle
Pete Finnigan
·
Publicado
2005-02-10
·
Atualizado
2017-07-11
·
CVE-2005-0298
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle versions 8i through 10g
Description
The issue concerns the DIRECTORY objects in the affected Oracle versions, which store the location of a specific operating system directory. This allows users with read privileges to a DIRECTORY object to access sensitive information.
Recommendations
For Oracle versions 8i through 10g, restrict read access to DIRECTORY objects to prevent unauthorized users from obtaining sensitive information. Consider revoking read privileges from users who do not require them.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Oracle