PT-2005-4017 · Oracle · Oracle Html Db
Alexander Kornbrust
·
Published
2005-10-14
·
Updated
2017-07-11
·
CVE-2005-3203
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Oracle HTML DB versions 1.3 through 1.3.6
Description
The manual installation of Oracle HTML DB stores the SYS password in install.lst in plaintext. This allows local users to gain privileges.
Recommendations
For Oracle HTML DB versions 1.3 through 1.3.6, consider removing or securing access to the install.lst file to prevent unauthorized access to the SYS password. As a temporary workaround, restrict local access to the system to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Html Db