Oracle Database Server 'Create session and trigger as SYSDBA' Remote Core RDBMS Vulnerability
11 Apr. 2012
Summary
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7.3, 11.2.0.1, and 11.2.0.2 allows remote authenticated users to affect integrity, related to SYSDBA.
Oracle Database Server is prone to a remote vulnerability in Core RDBMS.
The vulnerability can be exploited over the 'Oracle NET' protocol. For an exploit to succeed, the attacker must have 'Create session and trigger as SYSDBA' privileges.
Vendor Status:
Oracle as issued an update for this vulnerablity
Disclosure Timeline:
2011-July-19 Rev 1. Initial Release
2011-July-19 Rev 2. Modified Credit Statement and modified Notes in Oracle Sun Products Risk Matrix.
2011-July-21 Rev 3. Pete Finnigan added to the In-Depth Credit Statement.
2011-July-22 Rev 4. Andy Davis added to the Credit Statement.
2011-August-2 Rev 5. Modified supported versions affected for PeopleSoft Enterprise PeopleTools for CVE-2011-2275, CVE-2011-2280 and CVE-2011-2274.
2011-August-19 Rev 6. Modified supported versions affected for PeopleSoft Enterprise PeopleTools and Oracle VM VirtualBox.
2011-December-15 Rev 7. Updated the CVSS score and note for CVE-2011-1511.