PT-2006-1344 · Oracle · Oracle Database

Alexander Kornbrust

·

Publicado

2006-01-18

·

Atualizado

2018-10-19

·

CVE-2006-0270

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Oracle Database server version 10.2.0.1
Description The issue concerns the Transparent Data Encryption (TDE) Wallet component. It is reported that the TDE stores the master key without encryption, allowing local users to obtain the key via the SGA. This could potentially have significant impact, although the specifics of the attack vectors and the full extent of the impact are not detailed.
Recommendations For Oracle Database server version 10.2.0.1, consider restricting access to the TDE Wallet component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-0270

Produtos afetados

Oracle Database