CVE Database
/

CVE-2008-1811

Back to search

CVE-2008-1811

Published: Apr 16, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

Unspecified vulnerability in Oracle Application Express 3.0.1 has unspecified impact and remote authenticated attack vectors related to flows_030000.wwv_execute_immediate, aka APEX01. NOTE: the previous information was obtained from the April 2008 CPU. Oracle has not commented on reliable researcher claims that APEX01 is for insufficient authorization checks for SQL commands in the run_ddl function in flows_030000.wwv_execute_immediate, allowing privilege escalation by certain non-DBA remote authenticated users.

VendorProductVersions

n/a

n/a

affected
n/a

References

oracle-cpu-april-2008(41858)
vdb-entry
x_refsource_XF
ADV-2008-1267
vdb-entry
x_refsource_VUPEN
ADV-2008-1233
vdb-entry
x_refsource_VUPEN
1019855
vdb-entry
x_refsource_SECTRACK
29829
third-party-advisory
x_refsource_SECUNIA
HPSBMA02133
vendor-advisory
x_refsource_HP
29874
third-party-advisory
x_refsource_SECUNIA
SSRT061201
vendor-advisory
x_refsource_HP

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now