Oracle Database Server Installation Security Bypass Vulnerability
BID:26425
Info
Oracle Database Server Installation Security Bypass Vulnerability
| Bugtraq ID: | 26425 |
| Class: | Design Error |
| CVE: |
CVE-2007-6260 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 13 2007 12:00AM |
| Updated: | Dec 18 2007 08:04PM |
| Credit: | David Litchfield is credited with the discovery of this issue. |
| Vulnerable: |
Oracle Oracle11g Standard Edition One 11.1 6 Oracle Oracle11g Standard Edition 11.1 6 Oracle Oracle11g Enterprise Edition 11.1 6 Oracle Oracle10g Standard Edition 10.2 .3 Oracle Oracle10g Standard Edition 10.2 .2 Oracle Oracle10g Standard Edition 10.2 .1 Oracle Oracle10g Standard Edition 10.1 .5 Oracle Oracle10g Standard Edition 10.1 .4.2 Oracle Oracle10g Standard Edition 10.1 .4 Oracle Oracle10g Standard Edition 10.1 .0.5 Oracle Oracle10g Standard Edition 10.1 .0.4 Oracle Oracle10g Standard Edition 10.1 .0.3.1 Oracle Oracle10g Standard Edition 10.1 .0.3 Oracle Oracle10g Standard Edition 10.1 .0.2 Oracle Oracle10g Standard Edition 9.0.4 .0 Oracle Oracle10g Standard Edition 10.2 Oracle Oracle10g Personal Edition 10.2 .3 Oracle Oracle10g Personal Edition 10.2 .2 Oracle Oracle10g Personal Edition 10.2 .1 Oracle Oracle10g Personal Edition 10.1 .5 Oracle Oracle10g Personal Edition 10.1 .4 Oracle Oracle10g Personal Edition 10.1 .0.4 Oracle Oracle10g Personal Edition 10.1 .0.3.1 Oracle Oracle10g Personal Edition 10.1 .0.3 Oracle Oracle10g Personal Edition 10.1 .0.2 Oracle Oracle10g Personal Edition 9.0.4 .0 Oracle Oracle10g Personal Edition 10.2 Oracle Oracle10g Enterprise Edition 10.2 .3 Oracle Oracle10g Enterprise Edition 10.2 .2 Oracle Oracle10g Enterprise Edition 10.2 .1 Oracle Oracle10g Enterprise Edition 10.1 .5 Oracle Oracle10g Enterprise Edition 10.1 .5 Oracle Oracle10g Enterprise Edition 10.1 .4 Oracle Oracle10g Enterprise Edition 10.1 .0.4 Oracle Oracle10g Enterprise Edition 10.1 .0.3.1 Oracle Oracle10g Enterprise Edition 10.1 .0.3 Oracle Oracle10g Enterprise Edition 10.1 .0.2 Oracle Oracle10g Enterprise Edition 9.0.4 .0 Oracle Oracle10g Enterprise Edition 10.2 |
| Not Vulnerable: | |
Discussion
Oracle Database Server Installation Security Bypass Vulnerability
The Oracle Database Server installation process is prone to a security-bypass vulnerability because of a design error. A small window of time exists during the installation process where attackers can access SYS or SYSTEM accounts.
Successful attacks will compromise the application or provide a means to launch further attacks.
This issue affects Oracle 10g and 11g.
The Oracle Database Server installation process is prone to a security-bypass vulnerability because of a design error. A small window of time exists during the installation process where attackers can access SYS or SYSTEM accounts.
Successful attacks will compromise the application or provide a means to launch further attacks.
This issue affects Oracle 10g and 11g.
Exploit / POC
Oracle Database Server Installation Security Bypass Vulnerability
Attackers can exploit this issue by accessing affected applications with default account credentials.
Attackers can exploit this issue by accessing affected applications with default account credentials.
Solution / Fix
Oracle Database Server Installation Security Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Oracle Database Server Installation Security Bypass Vulnerability
References:
References:
- Oracle 11g/10g Installation Vulnerability (David Litchfield)
- Oracle Database Security Checklist (Oracle)
- Oracle Homepage (Oracle)
- Oracle 11g/10g Installation Vulnerability ("David Litchfield"
)