First published: Thu Feb 05 2009(Updated: )
Oracle Database Server 10.1, 10.2, and 11g grants directory WRITE permissions for arbitrary pathnames that are aliased in a CREATE OR REPLACE DIRECTORY statement, which allows remote authenticated users with CREATE ANY DIRECTORY privileges to gain SYSDBA privileges by aliasing the pathname of the password directory, and then overwriting the password file through UTL_FILE operations, a related issue to CVE-2006-7141.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Database | =10.1 | |
Oracle Database | =10.2 | |
Oracle Database | =11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-6065 is considered a high severity vulnerability due to the potential for remote authenticated users to gain SYSDBA privileges.
To fix CVE-2008-6065, restrict the CREATE ANY DIRECTORY privilege for users and update to the latest Oracle Database version with security patches.
CVE-2008-6065 affects Oracle Database Server versions 10.1, 10.2, and 11g.
Yes, remote authenticated users with CREATE ANY DIRECTORY privileges can exploit CVE-2008-6065 to gain elevated access.
CVE-2008-6065 significantly impacts database security by allowing unauthorized access to SYSDBA privileges through manipulated directory permissions.