PT-2005-4017 · Oracle · Oracle Html Db
Alexander Kornbrust
·
Publicado
2005-10-14
·
Atualizado
2017-07-11
·
CVE-2005-3203
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Oracle HTML DB versions 1.3 through 1.3.6
Description
The manual installation of Oracle HTML DB stores the SYS password in install.lst in plaintext. This allows local users to gain privileges.
Recommendations
For Oracle HTML DB versions 1.3 through 1.3.6, consider removing or securing access to the install.lst file to prevent unauthorized access to the SYS password. As a temporary workaround, restrict local access to the system to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Oracle Html Db