PT-2007-7136 · Oracle · Oracle 11G+3
Published
2007-12-06
·
Updated
2018-10-15
·
CVE-2007-6260
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Oracle 10g and 11g versions (affected versions not specified)
Description
The issue is related to the installation process using default passwords for accounts, allowing remote attackers to gain login access by connecting to the Listener. It is noted that when the Database Configuration Assistant (DBCA) is used at the end of the installation, most accounts are either disabled or have their passwords changed.
Recommendations
For Oracle 10g and 11g, consider changing the default passwords for accounts after installation to prevent unauthorized access.
As a temporary workaround, restrict access to the Listener to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Database Configuration Assistant
Listener
Oracle 10G
Oracle 11G