CVE Vulnerabilities

CVE-2005-3203

Published: Oct 14, 2005 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The manual installation of Oracle HTML DB (HTMLDB) 1.3 through 1.3.6 stores the SYS password in install.lst in plaintext, which allows local users to gain privileges.

Affected Software

Name Vendor Start Version End Version
Html_db Oracle 1.3 (including) 1.3 (including)
Html_db Oracle 1.3.6 (including) 1.3.6 (including)

References