Skip to content

CVE-2022-21392: Local Privilege Escalation via NMR SUID in Oracle Enterprise Manager

Notifications You must be signed in to change notification settings

mbadanoiu/CVE-2022-21392

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

3 Commits
 
 
 
 

Repository files navigation

CVE-2022-21392: Local Privilege Escalation via NMR SUID in Oracle Enterprise Manager

In Oracle installations, where the “nmr” binary is present and SUID-ed as “root”, due to insecure directory permissions, the “oracle” user can elevate his/her privileges to that of the “root” user by replacing the “nmr_macro_list” file.

Vendor Disclosure:

The vendor's disclosure and fix for this vulnerability can be found here.

Requirements:

This vulnerability requires:

  • Access on the local system as the "oracle" user (e.g. executing arbitrary Java code via a compromised Oracle Database)

Proof Of Concept:

More details and the exploitation process can be found in this PDF.

About

CVE-2022-21392: Local Privilege Escalation via NMR SUID in Oracle Enterprise Manager

Topics

Resources

Stars

Watchers

Forks