CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

You could've applied all 1,449 Oracle patches and still been hit by this attack

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5900

As cited

Copy frozen at (site build).

vulnerabilities

You could've applied all 1,449 Oracle patches and still been hit by this attack

Huntress documented a credential theft attack on an Oracle database that exploited a SQL injection in a public-facing web application, then used Java source code uploaded directly into Oracle's embedded Java Virtual Machine (JVM) to deploy a post-exploitation toolkit called khunt. The attack leveraged legitimate Oracle database functionality rather than unpatched vulnerabilities, meaning the July release of 1,449 patches would not have prevented it. Security experts attribute the success to misconfiguration that allowed Java compilation on a production server, a capability typically restricted to database administrators.

Why it matters: Organizations running Oracle databases need to disable Java compilation on production systems and restrict JVM access to database administrator accounts only, as attackers increasingly exploit legitimate database features rather than relying solely on patch gaps to gain persistence and move laterally.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

You could've applied all 1,449 Oracle patches and still been hit by this attack

Huntress documented a credential theft attack on an Oracle database that exploited a SQL injection in a public-facing web application, then used Java source code uploaded directly into Oracle's embedded Java Virtual Machine (JVM) to deploy a post-exploitation toolkit called khunt. The attack leveraged legitimate Oracle database functionality rather than unpatched vulnerabilities, meaning the July release of 1,449 patches would not have prevented it. Security experts attribute the success to misconfiguration that allowed Java compilation on a production server, a capability typically restricted to database administrators.

Why it matters: Organizations running Oracle databases need to disable Java compilation on production systems and restrict JVM access to database administrator accounts only, as attackers increasingly exploit legitimate database features rather than relying solely on patch gaps to gain persistence and move laterally.

VendorsOracle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary