PT-2006-3062 · Oracle · Oracle Database Server

N1V1Hd $3C41R3Exploitbugtraq

·

Publicado

2006-04-27

·

Atualizado

2018-10-18

·

CVE-2006-2081

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Oracle Database Server 10g Release 2
Description The issue allows local users to execute arbitrary SQL queries via the GET DOMAIN INDEX METADATA function in the DBMS EXPORT EXTENSION package. This is due to insecure privileges that facilitate the introduction of SQL, which is not related to special characters.
Recommendations For Oracle Database Server 10g Release 2, consider restricting access to the DBMS EXPORT EXTENSION package to minimize the risk of exploitation. As a temporary workaround, consider disabling the GET DOMAIN INDEX METADATA function until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-2081

Produtos afetados

Oracle Database Server