PT-2006-1344 · Oracle · Oracle Database

Alexander Kornbrust

·

Published

2006-01-18

·

Updated

2018-10-19

·

CVE-2006-0270

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Oracle Database server version 10.2.0.1
Description The issue concerns the Transparent Data Encryption (TDE) Wallet component. It is reported that the TDE stores the master key without encryption, allowing local users to obtain the key via the SGA. This could potentially have significant impact, although the specifics of the attack vectors and the full extent of the impact are not detailed.
Recommendations For Oracle Database server version 10.2.0.1, consider restricting access to the TDE Wallet component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-0270

Affected Products

Oracle Database