CVE-2006-0270 |
|
发布时间 :2006-01-18 06:03:00 | ||
修订时间 :2017-07-19 21:29:36 | ||||
NMCO |
[原文]Unspecified vulnerability in the Transparent Data Encryption (TDE) Wallet component of Oracle Database server 10.2.0.1 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB27. NOTE: Oracle has not disputed a reliable researcher report that TDA stores the master key without encryption, which allows local users to obtain the key via the SGA.
[CNNVD]Oracle 2006年1月更新修复多个安全漏洞(CNNVD-200601-236)
Oracle Database是一款商业性质大型数据库系统。
各种Oracle Database Server、Oracle Enterprise Manager、Oracle Application Server、Oracle Collaboration Suite、Oracle E-Business Suite、PeopleSoft Enterprise Portal、JD Edwards EnterpriseOne Tools、OneWorld Tools、Oracle Developer Suite和Oracle Workflow软件被发现多个漏洞影响。这些漏洞可能是本地或远程漏洞,影响Oracle产品的所有安全属性。攻击者可能利用这些漏洞破坏服务器的保密性、完整性或可用性,或执行任意代码。
- CVSS (基础分值)
CVSS分值: | 10 | [严重(HIGH)] |
机密性影响: | COMPLETE | [完全的信息泄露导致所有系统文件暴露] |
完整性影响: | COMPLETE | [系统完整性可被完全破坏] |
可用性影响: | COMPLETE | [可能导致系统完全宕机] |
攻击复杂度: | LOW | [漏洞利用没有访问限制 ] |
攻击向量: | NETWORK | [攻击者不需要获取内网访问权或本地访问权] |
身份认证: | NONE | [漏洞利用无需身份认证] |
- CWE (弱点类目)
CWE-310 | [密码学安全问题] |
- CPE (受影响的平台与产品)
产品及版本信息(CPE)暂不可用 |
- OVAL (用于检测的技术细节)
未找到相关OVAL定义 |
- 官方数据库链接
- 其它链接及资源
http://securitytracker.com/id?1015499 (UNKNOWN) SECTRACK 1015499 |
http://www.kb.cert.org/vuls/id/545804 (UNKNOWN) CERT-VN VU#545804 |
http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html (UNKNOWN) CONFIRM http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html |
http://www.red-database-security.com/advisory/oracle_tde_unencrypted_sga.html (UNKNOWN) MISC http://www.red-database-security.com/advisory/oracle_tde_unencrypted_sga.html |
http://www.securityfocus.com/archive/1/archive/1/422262/30/7400/threaded (UNKNOWN) BUGTRAQ 20060117 Oracle Database 10g Rel. 2- Transparent Data Encryption plaintext masterkey in SGA |
http://www.securityfocus.com/bid/16287 (UNKNOWN) BID 16287 |
http://www.vupen.com/english/advisories/2006/0243 (VENDOR_ADVISORY) VUPEN ADV-2006-0243 |
http://www.vupen.com/english/advisories/2006/0323 (VENDOR_ADVISORY) VUPEN ADV-2006-0323 |
https://exchange.xforce.ibmcloud.com/vulnerabilities/24186 (UNKNOWN) XF oracle-sga-masterkey-plaintext(24186) |
https://exchange.xforce.ibmcloud.com/vulnerabilities/24321 (UNKNOWN) XF oracle-january2006-update(24321) |
- 漏洞信息
Oracle 2006年1月更新修复多个安全漏洞 | |
危急 | 加密问题 |
2006-01-18 00:00:00 | 2007-03-30 00:00:00 |
远程 | |
Oracle Database是一款商业性质大型数据库系统。
各种Oracle Database Server、Oracle Enterprise Manager、Oracle Application Server、Oracle Collaboration Suite、Oracle E-Business Suite、PeopleSoft Enterprise Portal、JD Edwards EnterpriseOne Tools、OneWorld Tools、Oracle Developer Suite和Oracle Workflow软件被发现多个漏洞影响。这些漏洞可能是本地或远程漏洞,影响Oracle产品的所有安全属性。攻击者可能利用这些漏洞破坏服务器的保密性、完整性或可用性,或执行任意代码。 |
- 公告与补丁
- 漏洞信息
22565 | |
Oracle TDE Wallet SGA Cleartext Password Storage | |
Cryptographic, Information Disclosure | |
Loss of Confidentiality | |
Vendor Verified |
- 漏洞描述
- 时间线
2006-01-17 | Unknow |
Unknow | Unknow |
- 解决方案
Currently, there are no known workarounds or upgrades to correct this issue. However, Oracle has released a patch (Jan2006 Critical Patch Update) to address this vulnerability. |
- 相关参考
|
漏洞作者
Unknown or Incomplete |