4.6
CVSSv2

CVE-2005-1496

Published: 11/05/2005 Updated: 11/07/2017
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The DBMS_Scheduler in Oracle 10g allows remote attackers with CREATE JOB privileges to gain additional privileges by changing SESSION_USER to the SYS user.

Vulnerable Product Search on Vulmon Subscribe to Product

oracle oracle10g personal 10.1.0.3

oracle oracle10g standard 10.1.0.3.1

oracle application server 10.1.0.3

oracle oracle10g enterprise 10.1.0.3

oracle oracle10g enterprise 10.1.0.3.1

oracle oracle10g standard 10.1.0.2

oracle oracle10g personal 10.1.0.3.1

oracle oracle10g personal 10.1.0.2

oracle oracle10g standard 10.1.0.3

oracle oracle10g enterprise 10.1.0.2

oracle application server 10.1.0.2

oracle application server 10.1.0.3.1