Description
The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtain the session key and salt for arbitrary users, which leaks information about the cryptographic hash and makes it easier to conduct brute force password guessing attacks, aka "stealth password cracking vulnerability."
Exploits (3)
exploitdb
WORKING POC
by Esteban Martinez Fayo · pythonlocalmultiple
https://www.exploit-db.com/exploits/22069
References (8)
Core 8
Core References
Press/Media Coverage x_refsource_misc
http://www.darkreading.com/authentication/167901072/security/application-security/240007643/attack-easily-cracks-oracle-database-passwords.html
Patch, Vendor Advisory x_refsource_confirm
http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
Exploit, Third Party Advisory, VDB Entry exploit
x_refsource_exploit-db
http://www.exploit-db.com/exploits/22069
Press/Media Coverage x_refsource_misc
http://threatpost.com/en_us/blogs/flaw-oracle-logon-protocol-leads-easy-password-cracking-092012?utm_source=Threatpost&utm_medium=Tabs&utm_campaign=Today%27s+Most+Popular
Press/Media Coverage x_refsource_misc
http://arstechnica.com/security/2012/09/oracle-database-stealth-password-cracking-vulnerability/
Patch, Vendor Advisory x_refsource_confirm
http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/55651
Broken Link vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2013:150
Scores
EPSS
0.5492
EPSS Percentile
98.1%
Details
CWE
CWE-287
Status
published
Products (9)
oracle/database_server
10.2.0.3
oracle/database_server
10.2.0.4
oracle/database_server
10.2.0.5
oracle/database_server
11.1.0.7
oracle/database_server
11.2.0.2
oracle/database_server
11.2.0.3
oracle/primavera_p6_enterprise_project_portfolio_management
8.2
oracle/primavera_p6_enterprise_project_portfolio_management
8.3
oracle/primavera_p6_enterprise_project_portfolio_management
8.4
Published
Sep 21, 2012
Tracked Since
Feb 18, 2026