Oracle Database Authentication Protocol CVE-2012-3137 Security Bypass Vulnerability
BID:55651
Info
Oracle Database Authentication Protocol CVE-2012-3137 Security Bypass Vulnerability
| Bugtraq ID: | 55651 |
| Class: | Design Error |
| CVE: |
CVE-2012-3137 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 24 2012 12:00AM |
| Updated: | Jul 22 2016 02:00AM |
| Credit: | Esteban Martinez Fayo |
| Vulnerable: |
Oracle Primavera P6 Enterprise Project Portfolio Management 8.4 Oracle Primavera P6 Enterprise Project Portfolio Management 8.3 Oracle Primavera P6 Enterprise Project Portfolio Management 8.2 Oracle Database 11g Release 2 11.2.0.3 Oracle Database 11g Release 2 11.2.0.2 Oracle Database 11g Release 2 0 Oracle Database 11g Release 1 11.1.0.7 Oracle Database 11g Release 1 0 Oracle Database 10g Release 2 10.2 5 Oracle Database 10g Release 2 10.2.0.4 Oracle Database 10g Release 2 10.2.0.3 |
| Not Vulnerable: | |
Discussion
Oracle Database Authentication Protocol CVE-2012-3137 Security Bypass Vulnerability
Oracle Database is prone to a remote security-bypass vulnerability that affects the authentication protocol.
An attacker can exploit this issue to bypass the authentication process and gain unauthorized access to the database.
This vulnerability affects Oracle Database 11g Release 1 and 11g Release 2.
Oracle Database is prone to a remote security-bypass vulnerability that affects the authentication protocol.
An attacker can exploit this issue to bypass the authentication process and gain unauthorized access to the database.
This vulnerability affects Oracle Database 11g Release 1 and 11g Release 2.
Exploit / POC
Oracle Database Authentication Protocol CVE-2012-3137 Security Bypass Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Oracle Database Authentication Protocol CVE-2012-3137 Security Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Oracle Database Authentication Protocol CVE-2012-3137 Security Bypass Vulnerability
References:
References:
- CVE-2012-3137 (Mir M. Mirhashimali)
- Oracle database flaw deemed serious, could expose data (Kevin Mitnick)
- Oracle Homepage (Oracle)
- cpujul2016: Oracle Critical Patch Update Advisory - July 2016 (Oracle)
- Oracle Critical Patch Update Advisory - October 2012 (Oracle)