PT-2006-3062 · Oracle · Oracle Database Server

N1V1Hd $3C41R3Exploitbugtraq

·

Published

2006-04-27

·

Updated

2018-10-18

·

CVE-2006-2081

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Oracle Database Server 10g Release 2
Description The issue allows local users to execute arbitrary SQL queries via the GET DOMAIN INDEX METADATA function in the DBMS EXPORT EXTENSION package. This is due to insecure privileges that facilitate the introduction of SQL, which is not related to special characters.
Recommendations For Oracle Database Server 10g Release 2, consider restricting access to the DBMS EXPORT EXTENSION package to minimize the risk of exploitation. As a temporary workaround, consider disabling the GET DOMAIN INDEX METADATA function until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2081

Affected Products

Oracle Database Server