CVE-2012-1675
Oracle TNS Listener Checker
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
The TNS Listener, as used in Oracle Database 11g 11.1.0.7, 11.2.0.2, and 11.2.0.3, and 10g 10.2.0.3, 10.2.0.4, and 10.2.0.5, as used in Oracle Fusion Middleware, Enterprise Manager, E-Business Suite, and possibly other products, allows remote attackers to execute arbitrary database commands by performing a remote registration of a database (1) instance or (2) service name that already exists, then conducting a man-in-the-middle (MITM) attack to hijack database connections, aka "TNS Poison."
TNS Listener, tal como es usado en Oracle Database 11g 11.1.0.7, 11.2.0.2, y 11.2.0.3, y 10g 10.2.0.3, 10.2.0.4, y 10.2.0.5, y en Oracle Fusion Middleware, Enterprise Manager, E-Business Suite, y posiblemente otros productos, permite a atacantes remotos ejecutar comandos de base de datos arbitrarios realizando un registro remoto de (1) una instancia o (2) nombre de servicio de base de datos que ya existe y, a continuaciĆ³n, relizando un ataque de man-in-the-middle (MITM) para secuestrar conexiones de bases de datos. TambiĆ©n conocido como "TNS Poison."
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-03-16 CVE Reserved
- 2012-05-08 CVE Published
- 2017-10-12 First Exploit
- 2024-08-06 CVE Updated
- 2024-11-06 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://seclists.org/fulldisclosure/2012/Apr/343 | Mailing List | |
http://www.kb.cert.org/vuls/id/359816 | Third Party Advisory | |
http://www.securitytracker.com/id?1027000 | Third Party Advisory | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/75303 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://github.com/bongbongco/CVE-2012-1675 | 2017-10-12 | |
http://seclists.org/fulldisclosure/2012/Apr/204 | 2024-08-06 | |
http://www.securityfocus.com/bid/53308 | 2024-08-06 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oracle Search vendor "Oracle" | Database Server Search vendor "Oracle" for product "Database Server" | 10.2.0.3 Search vendor "Oracle" for product "Database Server" and version "10.2.0.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Database Server Search vendor "Oracle" for product "Database Server" | 10.2.0.4 Search vendor "Oracle" for product "Database Server" and version "10.2.0.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Database Server Search vendor "Oracle" for product "Database Server" | 10.2.0.5 Search vendor "Oracle" for product "Database Server" and version "10.2.0.5" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Database Server Search vendor "Oracle" for product "Database Server" | 11.1.0.7 Search vendor "Oracle" for product "Database Server" and version "11.1.0.7" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Database Server Search vendor "Oracle" for product "Database Server" | 11.2.0.2 Search vendor "Oracle" for product "Database Server" and version "11.2.0.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Database Server Search vendor "Oracle" for product "Database Server" | 11.2.0.3 Search vendor "Oracle" for product "Database Server" and version "11.2.0.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Database Server Search vendor "Oracle" for product "Database Server" | 11.2.0.4 Search vendor "Oracle" for product "Database Server" and version "11.2.0.4" | - |
Affected
|