PT-2008-3343 · Oracle · Oracle Application Express
Publicado
2008-04-16
·
Atualizado
2018-10-11
·
CVE-2008-1811
CVSS v2.0
5.5
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle Application Express version 3.0.1
Description
The issue is related to insufficient authorization checks for SQL commands in the
run ddl function in flows 030000.wwv execute immediate, allowing privilege escalation by certain non-DBA remote authenticated users. This can be exploited through remote authenticated attack vectors.Recommendations
For Oracle Application Express version 3.0.1, consider restricting access to the
flows 030000.wwv execute immediate function until a patch is available, and ensure that authorization checks are properly implemented for SQL commands in the run ddl function to prevent privilege escalation. At the moment, there is no information about a newer version that contains a fix for this vulnerability. Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Oracle Application Express