Vulnerability Description
The TNS Listener, as used in Oracle Database 11g 11.1.0.7, 11.2.0.2, and 11.2.0.3, and 10g 10.2.0.3, 10.2.0.4, and 10.2.0.5, as used in Oracle Fusion Middleware, Enterprise Manager, E-Business Suite, and possibly other products, allows remote attackers to execute arbitrary database commands by performing a remote registration of a database (1) instance or (2) service name that already exists, then conducting a man-in-the-middle (MITM) attack to hijack database connections, aka "TNS Poison."
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Database Server | 10.2.0.3 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2012-06/msg00018.htmlMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2012/Apr/204ExploitMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2012/Apr/343Mailing ListThird Party Advisory
- http://www.kb.cert.org/vuls/id/359816Third Party AdvisoryUS Government Resource
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:150Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/alert-cve-2012-1675-1608180.htVendor Advisory
- http://www.securityfocus.com/bid/53308ExploitThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1027000Third Party AdvisoryVDB Entry
- https://blogs.oracle.com/security/entry/security_alert_for_cve_2012Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75303VDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2012-06/msg00018.htmlMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2012/Apr/204ExploitMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2012/Apr/343Mailing ListThird Party Advisory
- http://www.kb.cert.org/vuls/id/359816Third Party AdvisoryUS Government Resource
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:150Third Party Advisory
FAQ
What is CVE-2012-1675?
CVE-2012-1675 is a vulnerability with a CVSS score of 7.5 (HIGH). The TNS Listener, as used in Oracle Database 11g 11.1.0.7, 11.2.0.2, and 11.2.0.3, and 10g 10.2.0.3, 10.2.0.4, and 10.2.0.5, as used in Oracle Fusion Middleware, Enterprise Manager, E-Business Suite, ...
How severe is CVE-2012-1675?
CVE-2012-1675 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-1675?
Check the references section above for vendor advisories and patch information. Affected products include: Oracle Database Server.