Description
dbsnmp in Oracle Intelligent Agent allows local users to gain privileges by setting the ORACLE_HOME environmental variable, which dbsnmp uses to find the nmiconf.tcl script.
Remediation
References
Related Vulnerabilities
math.js Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2017-1001002)
SharePoint CVE-2021-24104 Vulnerability (CVE-2021-24104)
WordPress Plugin Custom Tables 'key' Parameter Cross-Site Scripting (3.4.4)
SharePoint Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-8580)