Oracle Label Security Unauthorized Access Vulnerability

Oracle Label Security is a security application for Oracle Enterprise Database. It provides a graphical interface and can manage security at the table/schema level.

A vulnerability exists in Oracle Label Security that may allow a malicious user to gain unauthorized access to restricted data.

This issue is known to stem from the audit functionality, SET_LABEL, and SQL*Predicate functionality.

This issue only affects the additional security layer provided by Oracle Label Security.


 

Privacy Statement
Copyright 2010, SecurityFocus