Vulnerabilities > CVE-2010-0866 - Unspecified vulnerability in Oracle Database Server 11.1.0.7/11.2.0.1
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Unspecified vulnerability in the JavaVM component in Oracle Database 11.1.0.7 and 11.2.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Metasploit
description This module exploits a flaw (0 day) in DBMS_JVM_EXP_PERMS package that allows any user with create session privilege to grant themselves java IO privileges. Identified by David Litchfield. Works on 10g R2, 11g R1 and R2 (Windows only) id MSF:AUXILIARY/SQLI/ORACLE/JVM_OS_CODE_10G last seen 2020-05-24 modified 2017-07-24 published 2010-03-15 references reporter Rapid7 source https://github.com/rapid7/metasploit-framework/blob/master//modules/auxiliary/sqli/oracle/jvm_os_code_10g.rb title Oracle DB 10gR2, 11gR1/R2 DBMS_JVM_EXP_PERMS OS Command Execution description This module exploits a flaw (0 day) in DBMS_JVM_EXP_PERMS package that allows any user with create session privilege to grant themselves java IO privileges. Identified by David Litchfield. Works on 11g R1 and R2 (Windows only). id MSF:AUXILIARY/SQLI/ORACLE/JVM_OS_CODE_11G last seen 2020-05-21 modified 2017-07-24 published 2010-03-15 references reporter Rapid7 source https://github.com/rapid7/metasploit-framework/blob/master//modules/auxiliary/sqli/oracle/jvm_os_code_11g.rb title Oracle DB 11g R1/R2 DBMS_JVM_EXP_PERMS OS Code Execution
Nessus
NASL family | Databases |
NASL id | ORACLE_RDBMS_CPU_APR_2010.NASL |
description | The remote Oracle database server is missing the April 2010 Critical Patch Update (CPU) and therefore is potentially affected by security issues in the following components : - Core RDBMS - JavaVM - Change Data Capture - Audit |
last seen | 2020-06-02 |
modified | 2010-04-26 |
plugin id | 45626 |
published | 2010-04-26 |
reporter | This script is Copyright (C) 2010-2020 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/45626 |
title | Oracle Database Multiple Vulnerabilities (April 2010 CPU) |
code |
|