CVE-2008-6869 describes a vulnerability in Oramon Oracle Database Monitoring Tool version 2.0.1, where sensitive information, including credentials, is stored in config/oramon.ini under the web root with insufficient access control. This allows unauthenticated remote attackers to directly download the configuration file. The vulnerability has a CVSS score of 5.0, indicating a medium severity risk with potential for partial confidentiality impact due to unauthorized information disclosure. While not currently in CISA's KEV catalog, an ExploitDB entry (EDB-7286) exists, demonstrating exploitability, though there is no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.1CPE matchmatch criteria | cpe:2.3:a:oramon:oramon:2.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.