Record summary

CVE-2012-3137 has a selected CVSS score of 6.4; EIP currently links 1 catalogued exploit and 2 repository PoCs.

Description

The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtain the session key and salt for arbitrary users, which leaks information about the cryptographic hash and makes it easier to conduct brute force password guessing attacks, aka "stealth password cracking vulnerability."

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
2

Proofs of concept

3

Catalogued exploits

ExploitDBOracle Database - Protocol Authentication BypassExploitDB exploitby Esteban Martinez FayoNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubhantwister/o5logon-fetchRepository PoCby hantwisterStars: 3Not analyzed9 files

56.8 KiB

GitHub

PoC details
GitHubr1-/cve-2012-3137Repository PoCby r1-Stars: 4Not analyzed1 file

35.6 KiB

GitHub

PoC details

References

9