CVE-2005-1495: High severity Oracle Oracle10g vulnerability
Oracle Database 9i and 10g disables Fine Grained Audit (FGA) after the SYS user executes a SELECT statement on an FGA object, which makes it easier for attackers to escape detection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-1495?
CVE-2005-1495 is considered a medium severity vulnerability that allows attackers to evade detection through Fine Grained Audit (FGA) in Oracle products.
How does CVE-2005-1495 affect Oracle Database users?
CVE-2005-1495 impacts Oracle Database users by disabling Fine Grained Audit when the SYS user performs a SELECT on an FGA object, hindering accountability.
What versions of Oracle are affected by CVE-2005-1495?
CVE-2005-1495 affects Oracle Database 9i and 10g, including various versions of Oracle Application Server.
How can administrators mitigate CVE-2005-1495?
To mitigate CVE-2005-1495, administrators should limit the permissions of the SYS user and regularly monitor database activities.
Is there a patch available for CVE-2005-1495?
Yes, Oracle has released patches for affected versions addressing the vulnerability associated with CVE-2005-1495.