Multiple components in Oracle 9i Application Server (9iAS) are installed with over 160 default usernames and passwords, including (1) SYS, (2) SYSTEM, (3) AQJAVA, (4) OWA, (5) IMAGEUSER, (6) USER1, (7) USER2, (8) PLSQL, (9) DEMO, (10) FINANCE, and many others, which allows attackers to gain privileges.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/972 | vdb entry |
http://www.kb.cert.org/vuls/id/712723 | third party advisory us government resource |
http://www.nextgenss.com/papers/hpoas.pdf | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/968 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/971 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/969 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/970 | vdb entry |