Vulnerability Name: | CVE-2012-1675 (CCN-75303) | ||||||||
Assigned: | 2012-04-30 | ||||||||
Published: | 2012-04-30 | ||||||||
Updated: | 2018-08-23 | ||||||||
Summary: | The TNS Listener, as used in Oracle Database 11g 11.1.0.7, 11.2.0.2, and 11.2.0.3, and 10g 10.2.0.3, 10.2.0.4, and 10.2.0.5, as used in Oracle Fusion Middleware, Enterprise Manager, E-Business Suite, and possibly other products, allows remote attackers to execute arbitrary database commands by performing a remote registration of a database (1) instance or (2) service name that already exists, then conducting a man-in-the-middle (MITM) attack to hijack database connections, aka "TNS Poison." | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 6.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:H/RL:TF/RC:C)
6.7 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:H/RL:TF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Other | ||||||||
References: | Source: CCN Type: Full-disclosure Mailing List, Wed Apr 18 2012 - 16:03:00 CDT The history of a -probably- 13 years old Oracle bug: TNS Poison Source: MITRE Type: CNA CVE-2012-1675 Source: SUSE Type: Mailing List, Third Party Advisory SUSE-SU-2012:0765 Source: FULLDISC Type: Exploit, Mailing List, Third Party Advisory 20120418 The history of a -probably- 13 years old Oracle bug: TNS Poison Source: FULLDISC Type: Mailing List, Third Party Advisory 20120428 Oracle TNS Poison vulnerability is actually a 0day with no patch available Source: CERT-VN Type: Third Party Advisory, US Government Resource VU#359816 Source: MANDRIVA Type: Third Party Advisory MDVSA-2013:150 Source: CCN Type: Oracle Security Alert for CVE-2012-1675 Oracle Security Alert for CVE-2012-1675 Source: CONFIRM Type: Vendor Advisory http://www.oracle.com/technetwork/topics/security/alert-cve-2012-1675-1608180.html Source: CCN Type: OSVDB ID: 81475 Oracle Database Server TNS Listener Spoofing Remote Command Execution Source: BID Type: Exploit, Third Party Advisory, VDB Entry 53308 Source: CCN Type: BID-53308 Oracle Database Server 'TNS Listener' Remote Poisoning Vulnerability Source: SECTRACK Type: Third Party Advisory, VDB Entry 1027000 Source: CONFIRM Type: Vendor Advisory https://blogs.oracle.com/security/entry/security_alert_for_cve_2012 Source: XF Type: UNKNOWN oracledatabase-tnslistener-spoofing(75303) Source: XF Type: VDB Entry oracledatabase-tnslistener-spoofing(75303) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |