PT-2005-2491 · Oracle · Oracle Database

Alexander Kornbrust

·

Published

2005-05-11

·

Updated

2017-07-11

·

CVE-2005-1495

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Oracle Database versions 9i and 10g
Description The issue allows attackers to evade detection by disabling Fine Grained Audit (FGA) after the SYS user executes a SELECT statement on an FGA object.
Recommendations For Oracle Database versions 9i and 10g, consider restricting access to FGA objects to prevent unauthorized SELECT statements, which may help minimize the risk of detection evasion.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1495

Affected Products

Oracle Database