PT-1999-1629 · Oracle · Oracle Database Assistant+1
Published
1999-03-04
·
Updated
2017-12-19
·
CVE-1999-1256
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Oracle Database Assistant version 1.0 in Oracle 8.0.3 Enterprise Edition
Description:
The issue allows local users to obtain the database master password from the spoolmain.log file when a new database is created, as the password is stored in plaintext in this file.
Recommendations:
For Oracle Database Assistant 1.0 in Oracle 8.0.3 Enterprise Edition, consider restricting access to the spoolmain.log file to minimize the risk of password exposure until a fix is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle 8.0.3 Enterprise Edition
Oracle Database Assistant