QID 48239
Date Published: 2023-07-28
QID 48239: Remote Management Service Accepting Unencrypted Credentials Detected (Oracle Database)
A remote management service that accepts unencrypted credentials was detected on the target host.
Services like Oracle Database with basic auth are checked.
Sending login information without encryption can leave it vulnerable to interception by attackers on the same network using a "network sniffer." This can result in unauthorized access to sensitive data.
Solution
If possible, use alternate services that provide encryption.
Using strong cryptography, render all authentication credentials (such as passwords/phrases) unreadable during transmission.
Using strong cryptography, render all authentication credentials (such as passwords/phrases) unreadable during transmission.
Vendor References
CVEs related to QID 48239
Software Advisories
| Advisory ID | Software | Component | Link |
|---|