CVE-2004-1366
4.6
Vector
AV:L/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 3.9 / Impact: 6.4
Source: NVD
Description
Oracle 10g Database Server stores the password for the SYSMAN account in cleartext in the world-readable emoms.properties file, which could allow local users to gain DBA privileges.
Affected (87)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| Version release_1 | |
| Version 11.5.1 | |
| Version 9.0.1 | |
| Version 10.1.2 | |
| Version 10.1.0.2 | |
| Version enterprise_10.1.0.2 | |
| Version enterprise_8.0.5_.0.0 | |
| Version client_9.2.0.1 |
Related CWEs
References (16)
Source: cve@mitre.org
Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
PatchThird Party AdvisoryUS Government Resource
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatch
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.