PT-2008-3343 · Oracle · Oracle Application Express

Published

2008-04-16

·

Updated

2018-10-11

·

CVE-2008-1811

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Oracle Application Express version 3.0.1
Description The issue is related to insufficient authorization checks for SQL commands in the run ddl function in flows 030000.wwv execute immediate, allowing privilege escalation by certain non-DBA remote authenticated users. This can be exploited through remote authenticated attack vectors.
Recommendations For Oracle Application Express version 3.0.1, consider restricting access to the flows 030000.wwv execute immediate function until a patch is available, and ensure that authorization checks are properly implemented for SQL commands in the run ddl function to prevent privilege escalation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2008-1811

Affected Products

Oracle Application Express