MEDIUM · 6.8

CVE-2007-6260

The installation process for Oracle 10g and llg uses accounts with default passwords, which allows remote attackers to obtain login access by connecting to the Listener. NOTE: at the end of the insta...

Vulnerability Description

The installation process for Oracle 10g and llg uses accounts with default passwords, which allows remote attackers to obtain login access by connecting to the Listener. NOTE: at the end of the installation, if performed using the Database Configuration Assistant (DBCA), most accounts are disabled or their passwords are changed.

CVSS Score

6.8

MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
OracleDatabase ServerAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2007-6260?

CVE-2007-6260 is a vulnerability with a CVSS score of 6.8 (MEDIUM). The installation process for Oracle 10g and llg uses accounts with default passwords, which allows remote attackers to obtain login access by connecting to the Listener. NOTE: at the end of the insta...

How severe is CVE-2007-6260?

CVE-2007-6260 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-6260?

Check the references section above for vendor advisories and patch information. Affected products include: Oracle Database Server.