Overview
A vulnerability in the way Oracle handles views may allow an attacker to modify privileged database information.
Description
Database Views A view is a queryable aggregation of data from one or more tables that is stored and maintained. |
Impact
A remote attacker may be able to execute arbitrary SQL statements with elevated privileges. This may allow the attacker to access and modify sensitive information within an Oracle database. |
Solution
Apply Updates |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.red-database-security.com/advisory/oracle_modify_data_via_views.html
- http://www.oracle.com/technology/deploy/security/pdf/twp_security_checklist_db_database.pdf
- http://www.oracle.com/technology/deploy/security/db_security/htdocs/eus.html
- http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2006.html
- http://andrewmax.blogspot.com/2006/04/yet-another-security-alert.html
Acknowledgements
This vulnerability was reported by Alexander Kornbrust of Red Database Security. Red Database Security credits Jens Flasche, Dr. Christian Kleinew์hter, and Swen Thümmler with providing information regarding this issue. Information used in this document came from Oracle.
This document was written by Jeff Gennari and Stephen Rhoton.
Other Information
CVE IDs: | None |
Severity Metric: | 12.66 |
Date Public: | 2006-04-06 |
Date First Published: | 2006-05-03 |
Date Last Updated: | 2007-01-03 14:45 UTC |
Document Revision: | 107 |