PT-2004-1130 · Oracle+1 · Oracle+2

Publicado

2004-03-16

·

Atualizado

2017-07-11

·

CVE-2002-1578

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SAP R/3 versions using Oracle and SQL*net V2 3.x, 4.x, and 6.10
Description The issue allows remote attackers to obtain arbitrary, sensitive SAP data by directly connecting to the Oracle database and executing queries against it, as the database is not password-protected.
Recommendations For SAP R/3 using Oracle and SQL*net V2 3.x, 4.x, and 6.10, consider implementing password protection for the Oracle database to prevent unauthorized access. As a temporary workaround, restrict direct connections to the Oracle database until a more secure configuration can be implemented.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-1578

Produtos afetados

Oracle
Sap R/3
Sql*Net