Oracle provides database export functionality in various modes. One of the export modes is called Direct Path. This mode uses a special protocol message to extract table data rather than SQL queries. Using this special protocol message an attacker can extract information from tables and views to which she has not been granted access. Oracle 9 and 10 versions prior to April 2008 CPU are affected.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/65617/adc_advisories_oracle-dbms.txt
Source: https://packetstormsecurity.com/files/65617/adc_advisories_oracle-dbms.txt.html

