CVE-2007-6260
Last modified
CVE-2007-6260 is a vulnerability of currently unknown severity. The installation process for Oracle 10g and llg uses accounts with default passwords, which allows remote attackers to obtain login access by connecting to the Listener. NOTE: at the end of the installation, if performed using the Database Configuration Assistant (DBCA), most accounts are disabled or their passwords are changed.. EPSS estimates a 1.43% chance of exploitation in the next 30 days.
Description
The installation process for Oracle 10g and llg uses accounts with default passwords, which allows remote attackers to obtain login access by connecting to the Listener. NOTE: at the end of the installation, if performed using the Database Configuration Assistant (DBCA), most accounts are disabled or their passwords are changed.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Database Server | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-6260?
How severe is CVE-2007-6260?
How do I fix CVE-2007-6260?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-6252Multiple stack-based buffer overflows in the Learn2 Corporat…
- CVE-2007-6253Multiple buffer overflows in Adobe Form Designer 5.0 and For…
- CVE-2007-6254Stack-based buffer overflow in the SAP Business Objects Busi…
- CVE-2007-6255Buffer overflow in the Microsoft HeartbeatCtl ActiveX contro…
- CVE-2007-6256Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2007-6258Multiple stack-based buffer overflows in the legacy mod_jk2 …
- CVE-2007-6261Integer overflow in the load_threadstack function in the Mac…
- CVE-2007-6262A certain ActiveX control in axvlc.dll in VideoLAN VLC 0.8.6…
- CVE-2007-6263The dataconn function in ftpd.c in netkit ftpd (netkit-ftpd)…
- CVE-2007-6265Unspecified vulnerability in avast! 4 Home and Professional …
- CVE-2007-6266Multiple SQL injection vulnerabilities in bcoos 1.0.10 and e…
- CVE-2007-6267Citrix EdgeSight 4.2 and 4.5 for Presentation Server, EdgeSi…
Are you affected by CVE-2007-6260?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
