CVE-2004-1367
Last modified
CVE-2004-1367 is a vulnerability of currently unknown severity. Oracle 10g Database Server, when installed with a password that contains an exclamation point ("!") for the (1) DBSNMP or (2) SYSMAN user, generates an error that logs the password in the world-readable postDBCreation.log file, which could allow local users to obtain that password and use it against SYS or SYSTEM accounts, which may have been installed with the same password.. EPSS estimates a 7.27% chance of exploitation in the next 30 days.
Description
Oracle 10g Database Server, when installed with a password that contains an exclamation point ("!") for the (1) DBSNMP or (2) SYSMAN user, generates an error that logs the password in the world-readable postDBCreation.log file, which could allow local users to obtain that password and use it against SYS or SYSTEM accounts, which may have been installed with the same password.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Application Server | All versions |
| Oracle | Application Server | 9.0.2 |
| Oracle | Application Server | 9.0.2.0.0 |
| Oracle | Application Server | 9.0.2.0.1 |
| Oracle | Application Server | 9.0.2.1 |
| Oracle | Application Server | 9.0.2.2 |
| Oracle | Application Server | 9.0.2.3 |
| Oracle | Application Server | 9.0.3 |
| Oracle | Application Server | 9.0.3.1 |
| Oracle | Application Server | 9.0.4 |
| Oracle | Application Server | 9.0.4.0 |
| Oracle | Application Server | 9.0.4.1 |
| Oracle | Collaboration Suite | release_1 |
| Oracle | E-Business Suite | 11.5.1 |
| Oracle | E-Business Suite | 11.5.2 |
| Oracle | E-Business Suite | 11.5.3 |
| Oracle | E-Business Suite | 11.5.4 |
| Oracle | E-Business Suite | 11.5.5 |
| Oracle | E-Business Suite | 11.5.6 |
| Oracle | E-Business Suite | 11.5.7 |
| Oracle | E-Business Suite | 11.5.8 |
| Oracle | E-Business Suite | 11.5.9 |
| Oracle | Enterprise Manager | 9 |
| Oracle | Enterprise Manager | 9.0.1 |
| Oracle | Enterprise Manager Database Control | 10.1.2 |
| Oracle | Enterprise Manager Grid Control | 10.1.0.2 |
| Oracle | Oracle10g | enterprise_9.0.4_.0 |
| Oracle | Oracle10g | enterprise_10.1.0.2 |
| Oracle | Oracle10g | personal_9.0.4_.0 |
| Oracle | Oracle10g | personal_10.1_.0.2 |
| Oracle | Oracle10g | standard_9.0.4_.0 |
| Oracle | Oracle10g | standard_10.1_.0.2 |
| Oracle | Oracle8i | enterprise_8.0.5_.0.0 |
| Oracle | Oracle8i | enterprise_8.0.6_.0.0 |
| Oracle | Oracle8i | enterprise_8.0.6_.0.1 |
| Oracle | Oracle8i | enterprise_8.1.5_.0.0 |
| Oracle | Oracle8i | enterprise_8.1.5_.0.2 |
| Oracle | Oracle8i | enterprise_8.1.5_.1.0 |
| Oracle | Oracle8i | enterprise_8.1.6_.0.0 |
| Oracle | Oracle8i | enterprise_8.1.6_.1.0 |
| Oracle | Oracle8i | enterprise_8.1.7_.0.0 |
| Oracle | Oracle8i | enterprise_8.1.7_.1.0 |
| Oracle | Oracle8i | enterprise_8.1.7_.4 |
| Oracle | Oracle8i | standard_8.0.6 |
| Oracle | Oracle8i | standard_8.0.6_.3 |
| Oracle | Oracle8i | standard_8.1.5 |
| Oracle | Oracle8i | standard_8.1.6 |
| Oracle | Oracle8i | standard_8.1.7 |
| Oracle | Oracle8i | standard_8.1.7_.0.0 |
| Oracle | Oracle8i | standard_8.1.7_.1 |
Showing 50 of 87 affected configurations. See NVD for the full list.
References
- http://www.kb.cert.org/vuls/id/316206US Government Resource
- http://www.ngssoftware.com/advisories/oracle23122004D.txtPatch, Vendor Advisory
- http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdfPatch, Vendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA04-245A.htmlUS Government Resource
- http://www.kb.cert.org/vuls/id/316206US Government Resource
- http://www.ngssoftware.com/advisories/oracle23122004D.txtPatch, Vendor Advisory
- http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdfPatch, Vendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA04-245A.htmlUS Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-1367?
How severe is CVE-2004-1367?
How do I fix CVE-2004-1367?
Are you affected by CVE-2004-1367?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
