PT-2004-1130 · Oracle+1 · Oracle+2

Published

2004-03-16

·

Updated

2017-07-11

·

CVE-2002-1578

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SAP R/3 versions using Oracle and SQL*net V2 3.x, 4.x, and 6.10
Description The issue allows remote attackers to obtain arbitrary, sensitive SAP data by directly connecting to the Oracle database and executing queries against it, as the database is not password-protected.
Recommendations For SAP R/3 using Oracle and SQL*net V2 3.x, 4.x, and 6.10, consider implementing password protection for the Oracle database to prevent unauthorized access. As a temporary workaround, restrict direct connections to the Oracle database until a more secure configuration can be implemented.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1578

Affected Products

Oracle
Sap R/3
Sql*Net