← back
CVE-2008-6065

CVE-2008-6065

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 2.2%
from disclosure to weapon0 days
Published on NVDFeb 5
1st PoCOct 13
exploitation probability
2.2%top 19% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Oracle Database Server 10.1, 10.2, and 11g grants directory WRITE permissions for arbitrary pathnames that are aliased in a CREATE OR REPLACE DIRECTORY statement, which allows remote authenticated users with CREATE ANY DIRECTORY privileges to gain SYSDBA privileges by aliasing the pathname of the password directory, and then overwriting the password file through UTL_FILE operations, a related issue to CVE-2006-7141.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.