CVE-2012-3137 EXPLOIT
6.4
MEDIUM · CVSS 2.0 · EPSS 31.4% (pctl 98)
Patch early
A public exploit exists.
Description
The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtain the session key and salt for arbitrary users, which leaks information about the cryptographic hash and makes it easier to conduct brute force password guessing attacks, aka "stealth password cracking vulnerability."
Scoring
| CVSS | 6.4 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
| EPSS | 31.44% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-287 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2012-09-21 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| oracle | database server |
| oracle | primavera p6 enterprise project portfolio management |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Oracle Database - Protocol Authentication Bypass | 2012-10-18 |
References
- http://arstechnica.com/security/2012/09/oracle-database-stealth-password-cracking-vulnerability/
- http://threatpost.com/en_us/blogs/flaw-oracle-logon-protocol-leads-easy-password-cracking-092012?utm_source=Threatpost&utm_medium=Tabs&utm_campaign=Today%27s+Most+Popular
- http://www.darkreading.com/authentication/167901072/security/application-security/240007643/attack-easily-cracks-oracle-database-passwords.html
- http://www.exploit-db.com/exploits/22069
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:150
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html
- http://www.securityfocus.com/bid/55651
- http://arstechnica.com/security/2012/09/oracle-database-stealth-password-cracking-vulnerability/
- http://threatpost.com/en_us/blogs/flaw-oracle-logon-protocol-leads-easy-password-cracking-092012?utm_source=Threatpost&utm_medium=Tabs&utm_campaign=Today%27s+Most+Popular
- http://www.darkreading.com/authentication/167901072/security/application-security/240007643/attack-easily-cracks-oracle-database-passwords.html
- http://www.exploit-db.com/exploits/22069
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:150
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html
- http://www.securityfocus.com/bid/55651
→ the Explorer · watch your stack · NVD