CVE-2007-6260 Information
Feb 14, 2021
cve
Description
The installation process for Oracle 10g and llg uses accounts with default passwords which allows remote attackers to obtain login access by connecting to the Listener. NOTE: at the end of the installation if performed using the Database Configuration Assistant (DBCA) most accounts are disabled or their passwords are changed.
Reference
http://osvdb.org/43673 http://securityreason.com/securityalert/3419 http://www.davidlitchfield.com/blog/archives/00000030.htm http://www.oracle.com/technology/deploy/security/pdf/twp_security_checklist_db_database_20071108.pdf http://www.securityfocus.com/archive/1/483652/100/200/threaded http://www.securityfocus.com/bid/26425
Share on: