PT-2005-2491 · Oracle · Oracle Database
Alexander Kornbrust
·
Published
2005-05-11
·
Updated
2017-07-11
·
CVE-2005-1495
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Oracle Database versions 9i and 10g
Description
The issue allows attackers to evade detection by disabling Fine Grained Audit (FGA) after the SYS user executes a SELECT statement on an FGA object.
Recommendations
For Oracle Database versions 9i and 10g, consider restricting access to FGA objects to prevent unauthorized SELECT statements, which may help minimize the risk of detection evasion.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Database