Oracle Database Authentication Protocol Vulnerability
RISK: Medium Risk
TYPE: Servers - Database Servers
A vulnerability was identiified in Oracle Database. A remote user can determine user password hashes.
A remote user can send a few specially crafted network packets to obtain information about the session key and cryptographic salt for a target user. The information can be used to determine the cryptographic password hash.
The attack can be conducted without the database recording failed login attempts.
Impact
- Information Disclosure
System / Technologies affected
- Oracle Database 11g Releases 1 and 2
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- The vulnerability is reportedly fixed version 12 of the authentication protocol. Administrators must configure the system to use only version 12 of the protocol.
- No solution was available for version 11.1 of the authentication protocol at the time of this entry.
Vulnerability Identifier
Source
Related Link
Share with