CVE-2012-3137
Summary
| CVE | CVE-2012-3137 |
|---|---|
| State | PUBLISHED |
| Assigner | oracle |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-09-21 23:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtain the session key and salt for arbitrary users, which leaks information about the cryptographic hash and makes it easier to conduct brute force password guessing attacks, aka "stealth password cracking vulnerability." |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Oracle | Database Server | 10.2.0.3 | All | All | All |
| Application | Oracle | Database Server | 10.2.0.4 | All | All | All |
| Application | Oracle | Database Server | 10.2.0.5 | All | All | All |
| Application | Oracle | Database Server | 11.1.0.7 | All | All | All |
| Application | Oracle | Database Server | 11.2.0.2 | All | All | All |
| Application | Oracle | Database Server | 11.2.0.3 | All | All | All |
| Application | Oracle | Primavera P6 Enterprise Project Portfolio Management | 8.2 | All | All | All |
| Application | Oracle | Primavera P6 Enterprise Project Portfolio Management | 8.3 | All | All | All |
| Application | Oracle | Primavera P6 Enterprise Project Portfolio Management | 8.4 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Oracle Database Authentication Protocol Security Bypass | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| Flaw in Oracle Logon Protocol Leads to Easy Password Cracking | threatpost | af854a3a-2127-422b-91ae-364da2661108 | threatpost.com | Press/Media Coverage |
| Oracle Critical Patch Update - October 2012 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Vendor Advisory |
| Oracle Critical Patch Update - July 2016 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Vendor Advisory |
| Oracle Database Authentication Protocol CVE-2012-3137 Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Support / Security / Advisories / / MDVSA-2013:150 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | Broken Link |
| Attack Easily Cracks Oracle Database Passwords - Dark Reading | af854a3a-2127-422b-91ae-364da2661108 | www.darkreading.com | Press/Media Coverage |
| Oracle Database suffers from “stealth password cracking vulnerability” | Ars Technica | af854a3a-2127-422b-91ae-364da2661108 | arstechnica.com | Press/Media Coverage |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.