PT-2014-1281 · Oracle · Oracle Database Server+1
Publicado
2014-04-15
·
Atualizado
2014-04-29
·
CVE-2014-2406
CVSS v2.0
8.5
Alta
| Vetor | AV:N/AC:M/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Oracle Database Server versions 11.1.0.7 through 11.2.0.4
Oracle Database Server version 12.1.0.1
Description
The issue affects the Core RDBMS component in Oracle Database Server, allowing remote authenticated users to compromise confidentiality, integrity, and availability. This is related to "Advisor" and "Select Any Dictionary" privileges. The vulnerability can be exploited to bypass security restrictions, execute arbitrary SQL commands, and gain access to sensitive data.
Recommendations
For Oracle Database Server versions 11.1.0.7 through 11.2.0.4, consider restricting access to the Core RDBMS component until a patch is available.
For Oracle Database Server version 12.1.0.1, restrict privileges related to "Advisor" and "Select Any Dictionary" to minimize the risk of exploitation.
As a temporary workaround, consider disabling any functionality that allows remote authenticated users to execute arbitrary SQL commands until a patch is available.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Oracle Database
Oracle Database Server