#VU4237 Spoofing attack in Oracle Database Server - CVE-2012-1675
Published: January 11, 2017 / Updated: May 24, 2019
Oracle Database Server
Oracle
Description
The vulnerability exists due to an error in the TNS listener service. A remote attacker can register an existing instance or service name, use man-in-the-middle techniques and read, inject or modify transmitted data.
Successful exploitation of this vulnerability may result in unauthorized access to entire database.
Note: the vulnerability was being actively exploited.