VID |
25163 |
Severity |
30 |
Port |
1521, ... |
Protocol |
TCP |
Class |
DB |
Detailed Description |
WITH_GRANT_OPTION of ORACLE server on the host system is not set by role. A user having object privileges with the GRANT OPTION can grant privileges to other users as if he were the owner of the object. WITH_GRANT_OPTION must be set by role.
* Platforms Affected: UNIX any version Linux any version Microsoft Windows any version |
Recommendation |
Revoke the privilege by executing the following command and recreates the permission. SQL> REVOKE Role FROM <account> |
Related URL |
(CVE) |
Related URL |
(SecurityFocus) |
Related URL |
(ISS) |
|