Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

DB:ORACLE:INSECURE-TNS-LISTENER

Severity

Medium

Recommended

No

Category

DB

Keywords

Oracle Insecure TNS Listener Configuration

Release Date

2004/09/15

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

DB: Oracle Insecure TNS Listener Configuration


This signature detects an Oracle Database instance where the listener security options have been disabled, enabling database access for any connection (including attackers). Servers triggering this signature should be reviewed by a qualified Oracle DBA for security concerns.

Extended Description

A denial of service vulnerability exists in Oracle 8i. An attacker connecting to the host and sending a malformed SQLNet (Type-1) connection request, could cause the host to stop responding.

Affected Products

  • Oracle Oracle8 8.1.5
  • Oracle Oracle8 8.1.6
  • Oracle Oracle8 8.1.7

References

  • BugTraq: 2940
  • CVE: CVE-2001-0498
  • URL: http://www.securityfocus.com/archive/1/68924
  • URL: http://otn.oracle.com/deploy/security/pdf/listener_alert.pdf

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out