CVE Vulnerabilities

CVE-2012-3137

Improper Authentication

Published: Sep 21, 2012 | Modified: Nov 28, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
6.4 IMPORTANT
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu

The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtain the session key and salt for arbitrary users, which leaks information about the cryptographic hash and makes it easier to conduct brute force password guessing attacks, aka stealth password cracking vulnerability.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Database_server Oracle 10.2.0.3 (including) 10.2.0.3 (including)
Database_server Oracle 10.2.0.4 (including) 10.2.0.4 (including)
Database_server Oracle 10.2.0.5 (including) 10.2.0.5 (including)
Database_server Oracle 11.1.0.7 (including) 11.1.0.7 (including)
Database_server Oracle 11.2.0.2 (including) 11.2.0.2 (including)
Database_server Oracle 11.2.0.3 (including) 11.2.0.3 (including)

Potential Mitigations

References