4.4
CVE-2004-1367
- EPSS 7.28%
- Veröffentlicht 04.08.2004 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:07:33
- Erkennungen
Oracle 10g Database Server, when installed with a password that contains an exclamation point ("!") for the (1) DBSNMP or (2) SYSMAN user, generates an error that logs the password in the world-readable postDBCreation.log file, which could allow local users to obtain that password and use it against SYS or SYSTEM accounts, which may have been installed with the same password.Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oracle ≫ Application Server Version 9.0.2
Oracle ≫ Application Server Version 9.0.2.0.0
Oracle ≫ Application Server Version 9.0.2.0.1
Oracle ≫ Application Server Version 9.0.2.1
Oracle ≫ Application Server Version 9.0.2.2
Oracle ≫ Application Server Version 9.0.2.3
Oracle ≫ Application Server Version 9.0.3
Oracle ≫ Application Server Version 9.0.3.1
Oracle ≫ Application Server Version 9.0.4
Oracle ≫ Application Server Version 9.0.4.0
Oracle ≫ Application Server Version 9.0.4.1
Oracle ≫ Collaboration Suite Version release_1
Oracle ≫ E-business Suite Version 11.5.1
Oracle ≫ E-business Suite Version 11.5.2
Oracle ≫ E-business Suite Version 11.5.3
Oracle ≫ E-business Suite Version 11.5.4
Oracle ≫ E-business Suite Version 11.5.5
Oracle ≫ E-business Suite Version 11.5.6
Oracle ≫ E-business Suite Version 11.5.7
Oracle ≫ E-business Suite Version 11.5.8
Oracle ≫ E-business Suite Version 11.5.9
Oracle ≫ Enterprise Manager Version 9
Oracle ≫ Enterprise Manager Version 9.0.1
Oracle ≫ Enterprise Manager Database Control Version 10.1.2
Oracle ≫ Enterprise Manager Grid Control Version 10.1.0.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 7.28% | 0.936 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.4 | 3.4 | 6.4 |
AV:L/AC:M/Au:N/C:P/I:P/A:P
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1
http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf
http://www.us-cert.gov/cas/techalerts/TA04-245A.html
http://www.kb.cert.org/vuls/id/316206
http://www.ngssoftware.com/advisories/oracle23122004D.txt
http://marc.info/?l=bugtraq&m=110382247308064&w=2