공격자가 SQL 인젝션을 통해 Oracle 데이터베이스에 들어가 시스템 접근을 획득했습니다.
공격자는 공용 웹 애플리케이션의 SQL 인젝션 결함을 통해 Oracle 데이터베이스에 침투했습니다. 이후, 실행 파일을 디스크에 작성하지 않고도 포스트 익스플로잇 툴킷을 설치했습니다. 그들은 자바 소스 코드를 데이터베이스에 제공하고, Oracle이 이를 저장된 스키마 객체로 컴파일하도록 한 뒤, 데이터베이스 엔진 내부에서 명령을 실행했습니다.
Attackers accessed an Oracle database via SQL injection to gain system access.
Attackers broke into an organization's Oracle database through a SQL injection flaw in a public-facing web application. They installed a post-exploitation toolkit without writing an executable to disk. By feeding Java source code to the database, they allowed Oracle to compile it into stored schema objects and executed commands from within the database engine.