PT-2014-1281 · Oracle · Oracle Database Server+1

Published

2014-04-15

·

Updated

2014-04-29

·

CVE-2014-2406

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Oracle Database Server versions 11.1.0.7 through 11.2.0.4 Oracle Database Server version 12.1.0.1
Description The issue affects the Core RDBMS component in Oracle Database Server, allowing remote authenticated users to compromise confidentiality, integrity, and availability. This is related to "Advisor" and "Select Any Dictionary" privileges. The vulnerability can be exploited to bypass security restrictions, execute arbitrary SQL commands, and gain access to sensitive data.
Recommendations For Oracle Database Server versions 11.1.0.7 through 11.2.0.4, consider restricting access to the Core RDBMS component until a patch is available. For Oracle Database Server version 12.1.0.1, restrict privileges related to "Advisor" and "Select Any Dictionary" to minimize the risk of exploitation. As a temporary workaround, consider disabling any functionality that allows remote authenticated users to execute arbitrary SQL commands until a patch is available.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-00044
CVE-2014-2406

Affected Products

Oracle Database
Oracle Database Server