As cited
Copy frozen at (site build).
vulnerabilities
You could've applied all 1,449 Oracle patches and still been hit by this attack
Huntress documented a credential theft attack on an Oracle database that exploited a SQL injection in a public-facing web application, then used Java source code uploaded directly into Oracle's embedded Java Virtual Machine (JVM) to deploy a post-exploitation toolkit called khunt. The attack leveraged legitimate Oracle database functionality rather than unpatched vulnerabilities, meaning the July release of 1,449 patches would not have prevented it. Security experts attribute the success to misconfiguration that allowed Java compilation on a production server, a capability typically restricted to database administrators.
Why it matters: Organizations running Oracle databases need to disable Java compilation on production systems and restrict JVM access to database administrator accounts only, as attackers increasingly exploit legitimate database features rather than relying solely on patch gaps to gain persistence and move laterally.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
You could've applied all 1,449 Oracle patches and still been hit by this attack
Huntress documented a credential theft attack on an Oracle database that exploited a SQL injection in a public-facing web application, then used Java source code uploaded directly into Oracle's embedded Java Virtual Machine (JVM) to deploy a post-exploitation toolkit called khunt. The attack leveraged legitimate Oracle database functionality rather than unpatched vulnerabilities, meaning the July release of 1,449 patches would not have prevented it. Security experts attribute the success to misconfiguration that allowed Java compilation on a production server, a capability typically restricted to database administrators.
Why it matters: Organizations running Oracle databases need to disable Java compilation on production systems and restrict JVM access to database administrator accounts only, as attackers increasingly exploit legitimate database features rather than relying solely on patch gaps to gain persistence and move laterally.
- Source published
- First seen by Cybersecurity Tracker