Lucene search

K
zdiEmad Al-MousaZDI-21-083
HistoryJan 22, 2021 - 12:00 a.m.

Oracle Database Procedure Improper Privilege Management Privilege Escalation Vulnerability

2021-01-2200:00:00
Emad Al-Mousa
www.zerodayinitiative.com
38

0.026 Low

EPSS

Percentile

90.4%

This vulnerability allows local attackers to escalate privileges on affected installations of Oracle Database. Authentication is required to exploit this vulnerability. The specific flaw exists within the execution of stored procedures. When executing stored procedures, the process does not properly check the caller’s privileges. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from users with limited privileges.

0.026 Low

EPSS

Percentile

90.4%