CVE-2012-3137

Oracle Database Server - Info Disclosure

Title source: llm

Description

The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtain the session key and salt for arbitrary users, which leaks information about the cryptographic hash and makes it easier to conduct brute force password guessing attacks, aka "stealth password cracking vulnerability."

Exploits (3)

nomisec WORKING POC 4 stars
by r1- · poc
https://github.com/r1-/cve-2012-3137
nomisec WORKING POC 3 stars
by hantwister · poc
https://github.com/hantwister/o5logon-fetch
exploitdb WORKING POC
by Esteban Martinez Fayo · pythonlocalmultiple
https://www.exploit-db.com/exploits/22069

Scores

EPSS 0.5492
EPSS Percentile 98.0%

Classification

CWE
CWE-287
Status draft

Affected Products (9)

oracle/database_server
oracle/database_server
oracle/database_server
oracle/database_server
oracle/database_server
oracle/database_server
oracle/primavera_p6_enterprise_project_portfolio_management
oracle/primavera_p6_enterprise_project_portfolio_management
oracle/primavera_p6_enterprise_project_portfolio_management

Timeline

Published Sep 21, 2012
Tracked Since Feb 18, 2026