ID:30 - Exploit for Spoofing attack in Oracle Database Server - CVE-2012-1675
Published: March 18, 2020
Oracle Database Server
Link to public exploit:
Vulnerability description
The vulnerability exists due to an error in the TNS listener service. A remote attacker can register an existing instance or service name, use man-in-the-middle techniques and read, inject or modify transmitted data.
Successful exploitation of this vulnerability may result in unauthorized access to entire database.
Note: the vulnerability was being actively exploited.