PT-2008-3343 · Oracle · Oracle Application Express
Published
2008-04-16
·
Updated
2018-10-11
·
CVE-2008-1811
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle Application Express version 3.0.1
Description
The issue is related to insufficient authorization checks for SQL commands in the
run ddl function in flows 030000.wwv execute immediate, allowing privilege escalation by certain non-DBA remote authenticated users. This can be exploited through remote authenticated attack vectors.Recommendations
For Oracle Application Express version 3.0.1, consider restricting access to the
flows 030000.wwv execute immediate function until a patch is available, and ensure that authorization checks are properly implemented for SQL commands in the run ddl function to prevent privilege escalation. At the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Application Express