PT-2014-1281 · Oracle · Oracle Database Server+1
Published
2014-04-15
·
Updated
2014-04-29
·
CVE-2014-2406
CVSS v2.0
8.5
High
| Vector | AV:N/AC:M/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Oracle Database Server versions 11.1.0.7 through 11.2.0.4
Oracle Database Server version 12.1.0.1
Description
The issue affects the Core RDBMS component in Oracle Database Server, allowing remote authenticated users to compromise confidentiality, integrity, and availability. This is related to "Advisor" and "Select Any Dictionary" privileges. The vulnerability can be exploited to bypass security restrictions, execute arbitrary SQL commands, and gain access to sensitive data.
Recommendations
For Oracle Database Server versions 11.1.0.7 through 11.2.0.4, consider restricting access to the Core RDBMS component until a patch is available.
For Oracle Database Server version 12.1.0.1, restrict privileges related to "Advisor" and "Select Any Dictionary" to minimize the risk of exploitation.
As a temporary workaround, consider disabling any functionality that allows remote authenticated users to execute arbitrary SQL commands until a patch is available.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oracle Database
Oracle Database Server