PT-2004-1130 · Oracle+1 · Oracle+2
Publicado
2004-03-16
·
Atualizado
2017-07-11
·
CVE-2002-1578
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SAP R/3 versions using Oracle and SQL*net V2 3.x, 4.x, and 6.10
Description
The issue allows remote attackers to obtain arbitrary, sensitive SAP data by directly connecting to the Oracle database and executing queries against it, as the database is not password-protected.
Recommendations
For SAP R/3 using Oracle and SQL*net V2 3.x, 4.x, and 6.10, consider implementing password protection for the Oracle database to prevent unauthorized access.
As a temporary workaround, restrict direct connections to the Oracle database until a more secure configuration can be implemented.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Oracle
Sap R/3
Sql*Net