[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

251139

 
 

909

 
 

196159

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2012-1675Date: (C)2012-05-08   (M)2023-12-22


The TNS Listener, as used in Oracle Database 11g 11.1.0.7, 11.2.0.2, and 11.2.0.3, and 10g 10.2.0.3, 10.2.0.4, and 10.2.0.5, as used in Oracle Fusion Middleware, Enterprise Manager, E-Business Suite, and possibly other products, allows remote attackers to execute arbitrary database commands by performing a remote registration of a database (1) instance or (2) service name that already exists, then conducting a man-in-the-middle (MITM) attack to hijack database connections, aka "TNS Poison."

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.5
Exploit Score: 10.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1027000
http://seclists.org/fulldisclosure/2012/Apr/204
http://seclists.org/fulldisclosure/2012/Apr/343
BID-53308
MDVSA-2013:150
SUSE-SU-2012:0765
VU#359816
http://www.oracle.com/technetwork/topics/security/alert-cve-2012-1675-1608180.html
https://blogs.oracle.com/security/entry/security_alert_for_cve_2012
oracledatabase-tnslistener-spoofing(75303)

CPE    7
cpe:/a:oracle:database_server:11.2.0.2
cpe:/a:oracle:database_server:11.2.0.4
cpe:/a:oracle:database_server:11.2.0.3
cpe:/a:oracle:database_server:11.1.0.7
...
CWE    1
CWE-264

© SecPod Technologies