Oracle 9iAS Well Known Default Passwords Vulnerability
BID:4291
Info
Oracle 9iAS Well Known Default Passwords Vulnerability
| Bugtraq ID: | 4291 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 26 2002 12:00AM |
| Updated: | Feb 26 2002 12:00AM |
| Credit: | Reported by David Litchfield <[email protected]>. |
| Vulnerable: |
Oracle Oracle9i Application Server |
| Not Vulnerable: | |
Discussion
Oracle 9iAS Well Known Default Passwords Vulnerability
Oracle 9iAS creates up to 160 default user accounts during installation, depending on which compnents are installed. These accounts use well known default passwords, many of which are the same as the account names.
Oracle 9iAS creates up to 160 default user accounts during installation, depending on which compnents are installed. These accounts use well known default passwords, many of which are the same as the account names.
Exploit / POC
Oracle 9iAS Well Known Default Passwords Vulnerability
There is no exploit required for this issue.
There is no exploit required for this issue.
Solution / Fix
Oracle 9iAS Well Known Default Passwords Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.