peter bassill · operator
$ cve CVE-2012-3137 JSON

CVE-2012-3137 EXPLOIT

6.4
MEDIUM · CVSS 2.0 · EPSS 31.4% (pctl 98)

Patch early

A public exploit exists.

Description

The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtain the session key and salt for arbitrary users, which leaks information about the cryptographic hash and makes it easier to conduct brute force password guessing attacks, aka "stealth password cracking vulnerability."

Scoring

CVSS6.4 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
EPSS31.44% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploityes
Published2012-09-21
Last modified2026-06-16

Affected (2)

VendorProduct
oracledatabase server
oracleprimavera p6 enterprise project portfolio management

Public exploits

SourceTitleDate
exploit-dbOracle Database - Protocol Authentication Bypass2012-10-18

References

→ the Explorer  ·  watch your stack  ·  NVD