Lucene search

K
cve[email protected]CVE-2006-0270
HistoryJan 18, 2006 - 11:03 a.m.

CVE-2006-0270

2006-01-1811:03:00
CWE-310
web.nvd.nist.gov
23
oracle
database
server
vulnerability
tde wallet
oracle database server 10.2.0.1
cve-2006-0270

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

5.9 Medium

AI Score

Confidence

Low

0.008 Low

EPSS

Percentile

81.4%

Unspecified vulnerability in the Transparent Data Encryption (TDE) Wallet component of Oracle Database server 10.2.0.1 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB27. NOTE: Oracle has not disputed a reliable researcher report that TDA stores the master key without encryption, which allows local users to obtain the key via the SGA.

Affected configurations

NVD
Node
oracledatabase_serverMatch10.2.0.1

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

5.9 Medium

AI Score

Confidence

Low

0.008 Low

EPSS

Percentile

81.4%