Oracle 10g Database Server stores the password for the SYSMAN account in cleartext in the world-readable emoms.properties file, which could allow local users to gain DBA privileges.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/18661 | vdb entry |
http://www.securityfocus.com/archive/1/385323 | mailing list exploit patch |
http://www.kb.cert.org/vuls/id/316206 | third party advisory us government resource |
http://www.us-cert.gov/cas/techalerts/TA04-245A.html | us government resource third party advisory patch |
http://www.ngssoftware.com/advisories/oracle23122004D.txt | patch vendor advisory |
http://www.securityfocus.com/bid/10871 | vdb entry patch |
http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf | patch vendor advisory |
http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1 | vendor advisory |