CVE-2008-1811
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Unspecified vulnerability in Oracle Application Express 3.0.1 has unspecified impact and remote authenticated attack vectors related to flows_030000.wwv_execute_immediate, aka APEX01. NOTE: the previous information was obtained from the April 2008 CPU. Oracle has not commented on reliable researcher claims that APEX01 is for insufficient authorization checks for SQL commands in the run_ddl function in flows_030000.wwv_execute_immediate, allowing privilege escalation by certain non-DBA remote authenticated users.
Una vulnerabilidad no especificada en Oracle Application Express versión 3.0.1, presenta un impacto no especificado y vectores de ataque autenticados remotos relacionados con flows_030000.wwv_execute_immediate, también se conoce como APEX01. NOTA: la información anterior fue obtenida de la CPU de abril de 2008. Oracle no ha comentado sobre las afirmaciones de investigadores confiables que APEX01 está por comprobaciones de autorización insuficientes para comandos SQL en la función run_ddl en flows_030000.wwv_execute_immediate, lo que permite una escalada de privilegios por parte de un determinado usuario autenticado remoto sin DBA.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-04-15 CVE Reserved
- 2008-04-16 CVE Published
- 2024-08-07 CVE Updated
- 2024-09-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=690 | Third Party Advisory | |
http://www.oracle.com/technetwork/topics/security/cpuapr2008-082075.html | X_refsource_confirm | |
http://www.securitytracker.com/id?1019855 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/41858 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/41988 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/29829 | 2018-10-11 | |
http://secunia.com/advisories/29874 | 2018-10-11 | |
http://www.securityfocus.com/archive/1/491024/100/0/threaded | 2018-10-11 | |
http://www.vupen.com/english/advisories/2008/1233/references | 2018-10-11 | |
http://www.vupen.com/english/advisories/2008/1267/references | 2018-10-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oracle Search vendor "Oracle" | Application Express Search vendor "Oracle" for product "Application Express" | 3.0.1 Search vendor "Oracle" for product "Application Express" and version "3.0.1" | - |
Affected
|