关于 CVE-2015-0393 的漏洞信息

1. 漏洞描述
From NVD
Unspecified vulnerability in the Oracle Applications DBA component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to DB Privileges. NOTE: the previous information is from the January 2015 CPU. Oracle has not commented on the researcher's claim that the PUBLIC role is granted the INDEX privilege for the DUAL table during a "seeded install," which allows remote authenticated users to gain SYSDBA privileges and execute arbitrary code.
From 神龙GPT (AIGC)
Oracle E-Business Suite 11.5.10.2、12.0.6、12.1.3、12.2.2、12.2.3和12.2.4中的Oracle应用程序DBA组件存在未描述的漏洞,允许远程授权用户通过与数据库权限相关的未知向量影响机密性、完整性和可用性。注意:以前的信息来自2015年1月CPU。Oracle尚未对研究人员声称的“预先安装”过程中 public role 为 DUAL 表授予索引权限一事发表评论。
2. 漏洞评分(CVSS)
From NVD
NVD 暂无评分
From 神龙GPT (AIGC)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
3. 漏洞类别
From NVD
NVD 暂无漏洞类别信息
From 神龙GPT (AIGC)
神龙GPT 暂无漏洞类别信息(请耐心等待)
Reference