First published: Wed May 11 2005(Updated: )
The DBMS_Scheduler in Oracle 10g allows remote attackers with CREATE JOB privileges to gain additional privileges by changing SESSION_USER to the SYS user.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Oracle10g | =personal_10.1.0.3 | |
Oracle Oracle10g | =standard_10.1.0.3.1 | |
Oracle Application Server | =10.1.0.3 | |
Oracle Oracle10g | =enterprise_10.1.0.3 | |
Oracle Oracle10g | =enterprise_10.1.0.3.1 | |
Oracle Oracle10g | =standard_10.1.0.2 | |
Oracle Oracle10g | =personal_10.1.0.3.1 | |
Oracle Oracle10g | =personal_10.1.0.2 | |
Oracle Oracle10g | =standard_10.1.0.3 | |
Oracle Oracle10g | =enterprise_10.1.0.2 | |
Oracle Application Server | =10.1.0.2 | |
Oracle Application Server | =10.1.0.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.