Unrated severityNVD Advisory· Published May 11, 2005· Updated Apr 16, 2026
CVE-2005-1496
CVE-2005-1496
Description
The DBMS_Scheduler in Oracle 10g allows remote attackers with CREATE JOB privileges to gain additional privileges by changing SESSION_USER to the SYS user.
Affected products
12cpe:2.3:a:oracle:application_server:10.1.0.2:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:oracle:application_server:10.1.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:application_server:10.1.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:application_server:10.1.0.3.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:oracle10g:enterprise_10.1.0.2:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:oracle:oracle10g:enterprise_10.1.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:oracle10g:enterprise_10.1.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:oracle10g:enterprise_10.1.0.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:oracle10g:personal_10.1.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:oracle10g:personal_10.1.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:oracle10g:personal_10.1.0.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:oracle10g:standard_10.1.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:oracle10g:standard_10.1.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:oracle10g:standard_10.1.0.3.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.red-database-security.com/exploits/oracle_exploit_dbms_scheduler_select_user.htmlnvdExploitPatch
- www.securityfocus.com/bid/13509nvdExploitVendor Advisory
- marc.infonvd
- exchange.xforce.ibmcloud.com/vulnerabilities/20410nvd
News mentions
0No linked articles in our index yet.