Tanel Poder has found a way to get SYSDBA access to the Oracle database by utilizing a user who has the BECOME USER system privilege, execute privileges on KUPP$PROC.CHANGE_USER and CREATE SESSION.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/60864/oracle-sysdba.txt
Source: https://packetstormsecurity.com/files/60864/oracle-sysdba.txt.html

