The DBMS_Scheduler in Oracle 10g allows remote attackers with CREATE JOB privileges to gain additional privileges by changing SESSION_USER to the SYS user.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2005-05-10 21:00
Updated : 2017-07-10 18:32
NVD link : CVE-2005-1496
Mitre link : CVE-2005-1496
JSON object : View
CWE
Products Affected
oracle
- application_server
- oracle10g