Oracle 10g Database Server, when installed with a password that...
Vulnerability Description
Oracle 10g Database Server, when installed with a password that contains an exclamation point ("!") for the (1) DBSNMP or (2) SYSMAN user, generates an error that logs the password in the world-readable postDBCreation.log file, which could allow local users to obtain that password and use it against SYS or SYSTEM accounts, which may have been installed with the same password.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2004-1367
Credits & Attribution
No credits recorded in the NVD database.
References
- http://marc.info/?l=bugtraq&m=110382247308064&w=2
- http://www.kb.cert.org/vuls/id/316206
- http://www.us-cert.gov/cas/techalerts/TA04-245A.html
- http://www.ngssoftware.com/advisories/oracle23122004D.txt
- http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1
More from oracle
View All →Affected Vendor
oracle
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.