Oracle.DBMS.Login.Trigger.AUTH_ALTER_SESSION.Bypass

description-logoDescription

This indicates an attack attempt against an access control bypass vulnerability in Oracle Database.
This vulnerability is due to the software's inability to properly handle a logon trigger. A remote attacker could exploit this to bypass the AUTH_ALTER_SESSION security policies.

affected-products-logoAffected Products

Oracle Enterprise Search version 10.1.0.5 and 10.2.0.3

Impact logoImpact

System compromise

recomended-action-logoRecommended Actions

Apply the patch, available from the following web site:

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)