CVE-2012-1675, known as "TNS Poison," is a critical vulnerability affecting Oracle Database 10g and 11g, as well as various Oracle Fusion Middleware, Enterprise Manager, and E-Business Suite products. This flaw allows remote attackers to execute arbitrary database commands by registering a duplicate database instance or service name, enabling a man-in-the-middle attack to hijack existing database connections. With a CVSS score of 7.5 and a FAUCET Risk Score of 99/100, this vulnerability is highly severe, requiring no authentication and low attack complexity for a complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, a Metasploit module exists for checking its presence, and it has garnered significant community discussion and media coverage, indicating its historical importance and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.2.0.3CPE matchmatch criteria | cpe:2.3:a:oracle:database_server:10.2.0.3:*:*:*:*:*:*:* | ||
10.2.0.4CPE matchmatch criteria | cpe:2.3:a:oracle:database_server:10.2.0.4:*:*:*:*:*:*:* | ||
10.2.0.5CPE matchmatch criteria | cpe:2.3:a:oracle:database_server:10.2.0.5:*:*:*:*:*:*:* | ||
11.1.0.7CPE matchmatch criteria | cpe:2.3:a:oracle:database_server:11.1.0.7:*:*:*:*:*:*:* | ||
11.2.0.2CPE matchmatch criteria | cpe:2.3:a:oracle:database_server:11.2.0.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.