CVE Vulnerabilities

CVE-2012-3137

Improper Authentication

Published: Sep 21, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtain the session key and salt for arbitrary users, which leaks information about the cryptographic hash and makes it easier to conduct brute force password guessing attacks, aka stealth password cracking vulnerability.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Database_serverOracle10.2.0.3 (including)10.2.0.3 (including)
Database_serverOracle10.2.0.4 (including)10.2.0.4 (including)
Database_serverOracle10.2.0.5 (including)10.2.0.5 (including)
Database_serverOracle11.1.0.7 (including)11.1.0.7 (including)
Database_serverOracle11.2.0.2 (including)11.2.0.2 (including)
Database_serverOracle11.2.0.3 (including)11.2.0.3 (including)

Potential Mitigations

References