PT-2008-3343 · Oracle · Oracle Application Express

Publicado

2008-04-16

·

Atualizado

2018-10-11

·

CVE-2008-1811

CVSS v2.0

5.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Oracle Application Express version 3.0.1
Description The issue is related to insufficient authorization checks for SQL commands in the run ddl function in flows 030000.wwv execute immediate, allowing privilege escalation by certain non-DBA remote authenticated users. This can be exploited through remote authenticated attack vectors.
Recommendations For Oracle Application Express version 3.0.1, consider restricting access to the flows 030000.wwv execute immediate function until a patch is available, and ensure that authorization checks are properly implemented for SQL commands in the run ddl function to prevent privilege escalation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2008-1811

Produtos afetados

Oracle Application Express