CVE-2012-1675
published 2012-05-08CVE-2012-1675: The TNS Listener, as used in Oracle Database 11g 11.1.0.7, 11.2.0.2, and 11.2.0.3, and 10g 10.2.0.3, 10.2.0.4, and 10.2.0.5, as used in Oracle Fusion…
PriorityP275high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
77.63%
99.5th percentile
The TNS Listener, as used in Oracle Database 11g 11.1.0.7, 11.2.0.2, and 11.2.0.3, and 10g 10.2.0.3, 10.2.0.4, and 10.2.0.5, as used in Oracle Fusion Middleware, Enterprise Manager, E-Business Suite, and possibly other products, allows remote attackers to execute arbitrary database commands by performing a remote registration of a database (1) instance or (2) service name that already exists, then conducting a man-in-the-middle (MITM) attack to hijack database connections, aka "TNS Poison."
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect unauthorized TNS Listener registration attempts: monitor for remote registration of a database instance or service name that already exists on the TNS Listener port. ↗
- →Probe detection: a TNS registration packet sent to the listener that does NOT result in an error response indicates a vulnerable (and potentially exploited) target; alert on successful remote TNS service/instance registrations from unexpected sources. ↗
- →Scope detection broadly: TNS Poison affects Oracle Database 10g and 11g components used across Fusion Middleware, Enterprise Manager, and E-Business Suite — monitor TNS Listener traffic on all deployments of these products. ↗
- ·Affected versions are Oracle Database 11g (11.1.0.7, 11.2.0.2, 11.2.0.3) and 10g (10.2.0.3, 10.2.0.4, 10.2.0.5); detection rules should be scoped to these versions to reduce false positives on patched instances. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://lists.opensuse.org/opensuse-security-announce/2012-06/msg00018.htmlhttp://seclists.org/fulldisclosure/2012/Apr/204http://seclists.org/fulldisclosure/2012/Apr/343http://www.kb.cert.org/vuls/id/359816http://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.oracle.com/technetwork/topics/security/alert-cve-2012-1675-1608180.htmlhttp://www.securityfocus.com/bid/53308http://www.securitytracker.com/id?1027000https://blogs.oracle.com/security/entry/security_alert_for_cve_2012https://exchange.xforce.ibmcloud.com/vulnerabilities/75303http://lists.opensuse.org/opensuse-security-announce/2012-06/msg00018.htmlhttp://seclists.org/fulldisclosure/2012/Apr/204http://seclists.org/fulldisclosure/2012/Apr/343http://www.kb.cert.org/vuls/id/359816http://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.oracle.com/technetwork/topics/security/alert-cve-2012-1675-1608180.htmlhttp://www.securityfocus.com/bid/53308http://www.securitytracker.com/id?1027000https://blogs.oracle.com/security/entry/security_alert_for_cve_2012https://exchange.xforce.ibmcloud.com/vulnerabilities/75303
2012-05-08
Published