PT-2004-2284 · Oracle · Oracle 10G Database Server

David Litchfield

·

Published

2004-08-04

·

Updated

2016-10-18

·

CVE-2004-1367

CVSS v2.0

4.4

Medium

VectorAV:L/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Oracle 10g Database Server (affected versions not specified)
Description: The issue arises when the Oracle 10g Database Server is installed with a password containing an exclamation point for the DBSNMP or SYSMAN user. This results in an error that logs the password in the world-readable postDBCreation.log file. Local users could potentially obtain the password and use it to access SYS or SYSTEM accounts if they were installed with the same password.
Recommendations: For Oracle 10g Database Server, consider changing the passwords for the DBSNMP and SYSMAN users to not include an exclamation point, and restrict access to the postDBCreation.log file to prevent unauthorized users from obtaining the password. Additionally, ensure that the SYS and SYSTEM accounts do not use the same password as the DBSNMP or SYSMAN users to minimize potential damage.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2004-1367

Affected Products

Oracle 10G Database Server