PT-2005-2492 · Oracle · Oracle 10G

Alexander Kornbrust

·

Published

2005-05-11

·

Updated

2017-07-11

·

CVE-2005-1496

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Oracle 10g
Description The issue allows remote attackers with CREATE JOB privileges to gain additional privileges. This is achieved by changing the SESSION USER to the SYS user, potentially leading to elevated access.
Recommendations For Oracle 10g, consider restricting the CREATE JOB privilege to minimize the risk of exploitation. As a temporary workaround, monitor and limit changes to the SESSION USER, especially attempts to switch to the SYS user, until a more permanent solution is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1496

Affected Products

Oracle 10G