Oracle Database Vault component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.2 allows remote authenticated users to affect integrity and availability via unknown vectors related to Privileged Account.
Oracle Database Server is prone to a remote security-bypass vulnerability in Database Vault. The vulnerability can be exploited over the 'Oracle Net' protocol. For an exploit to succeed, the attacker must have 'Privileged Account' privileges. An attacker can exploit this issue to bypass certain security protections and change any user's password. Successfully exploiting this issue may lead to other attacks.
Vendor Status:
Oracle has issued an update to correct this vulnerability