Oracle Database DBMS_JAVA.SET_OUTPUT_TO_JAVA Privilege Escalation
| TSL ID | FSC20100208-02 |
| CVE ID(s) | Not available. |
| Severity | Critical |
| Description | A vulnerability has been reported in Oracle Database 11g server that could allow users with limited privileges to execute SQL commands with SYS privileges on the server. The vulnerability is due to an access control weakness that allows non-privileged users to execute methods in the DBMS_JAVA package. Remote authenticated users with only CREATE_SESSION privileges can exploit this vulnerability via the ISET_OUTPUT_TO_JAVA method and execute arbitrary SQL commands on the target server. The vendor, Oracle, has not released any patch to address this vulnerability as of yet. As a workaround, allow only trusted users to access the server. |
| Affected Products |
|
| CVSS Score |
Base 6.0 (AV:N/AC:M/Au:S/C:P/I:P/A:P):
|