ID:30 - Exploit for Spoofing attack in Oracle Database Server - CVE-2012-1675

 
Main Vulnerability Database Exploits ID:30 - Exploit for Spoofing attack in Oracle Database Server - CVE-2012-1675

ID:30 - Exploit for Spoofing attack in Oracle Database Server - CVE-2012-1675

Published: March 18, 2020


Vulnerability identifier: #VU4237
Vulnerability risk: High
CVE-ID: CVE-2012-1675
CWE-ID: CWE-300
Exploitation vector: Remote access
Vulnerable software:
Oracle Database Server

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to an error in the TNS listener service. A remote attacker can register an existing instance or service name, use man-in-the-middle techniques and read, inject or modify transmitted data.

Successful exploitation of this vulnerability may result in unauthorized access to entire database.

Note: the vulnerability was being actively exploited.


Remediation

Install update from vendor's website.