arstechnica.com
http://arstechnica.com/security/2012/09/oracle-database-stealth-password-cracking-vulnerability CVE-2012-3137
Oracle Database - Protocol Authentication Bypass
Record summary
CVE-2012-3137 has a selected CVSS score of 6.4; EIP currently links 1 catalogued exploit and 2 repository PoCs.
Description
The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtain the session key and salt for arbitrary users, which leaks information about the cryptographic hash and makes it easier to conduct brute force password guessing attacks, aka "stealth password cracking vulnerability."
Description source: CVE List
Exploitation context
Proofs of concept
3Catalogued exploits
ExploitDBOracle Database - Protocol Authentication BypassExploitDB exploitby Esteban Martinez FayoNot analyzed1 file
Repository PoCs
GitHubhantwister/o5logon-fetchRepository PoCby hantwisterStars: 3Not analyzed9 files
GitHubr1-/cve-2012-3137Repository PoCby r1-Stars: 4Not analyzed1 file
References
9threatpost.com
http://threatpost.com/en_us/blogs/flaw-oracle-logon-protocol-leads-easy-password-cracking-092012 darkreading.com
http://www.darkreading.com/authentication/167901072/security/application-security/240007643/attack-easily-cracks-oracle-database-passwords.html 22069exploit
http://www.exploit-db.com/exploits/22069 MDVSA-2013:150Vendor advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2013:150 oracle.comConfirmation
http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html oracle.comConfirmation
http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html 55651vdb entry
http://www.securityfocus.com/bid/55651 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2012-3137