CVE-2012-3137
The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtain the session key and salt for arbitrary users, which leaks information about the cryptographic hash and…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 31.4%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtain the session key and salt for arbitrary users, which leaks information about the cryptographic hash and makes it easier to conduct brute force password guessing attacks, aka "stealth password cracking vulnerability."
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 31.44% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- oracle/database server · oracle/primavera p6 enterprise project portfolio management
- Source
- secalert_us@oracle.com
References
- http://arstechnica.com/security/2012/09/oracle-database-stealth-password-cracking-vulnerability/Press/Media Coverage
- http://threatpost.com/en_us/blogs/flaw-oracle-logon-protocol-leads-easy-password-cracking-092012?utm_source=Threatpost&utm_medium=Tabs&utm_campaign=Today%27s+Most+PopularPress/Media Coverage
- http://www.darkreading.com/authentication/167901072/security/application-security/240007643/attack-easily-cracks-oracle-database-passwords.htmlPress/Media Coverage
- http://www.exploit-db.com/exploits/22069Exploit, Third Party Advisory, VDB Entry
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:150Broken Link
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlPatch, Vendor Advisory
- http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/55651
- http://arstechnica.com/security/2012/09/oracle-database-stealth-password-cracking-vulnerability/Press/Media Coverage
- http://threatpost.com/en_us/blogs/flaw-oracle-logon-protocol-leads-easy-password-cracking-092012?utm_source=Threatpost&utm_medium=Tabs&utm_campaign=Today%27s+Most+PopularPress/Media Coverage
- http://www.darkreading.com/authentication/167901072/security/application-security/240007643/attack-easily-cracks-oracle-database-passwords.htmlPress/Media Coverage
- http://www.exploit-db.com/exploits/22069Exploit, Third Party Advisory, VDB Entry
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:150Broken Link
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlPatch, Vendor Advisory
- http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/55651
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.