CVE-2012-3137: Oracle Database Server
Medium severity, CVSS 6.4. EPSS: 31.4% chance of exploitation in the next 30 days.
The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtain the session key and salt for arbitrary users, which leaks information about the cryptographic hash and makes it easier to conduct brute force password guessing attacks, aka "stealth password cracking vulnerability."
Affected products
- Oracle Database Server: version 10.2.0.3 only; version 10.2.0.4 only; version 10.2.0.5 only; version 11.1.0.7 only; version 11.2.0.2 only; version 11.2.0.3 only
- Oracle Primavera p6 Enterprise Project Portfolio Management: version 8.2 only; version 8.3 only; version 8.4 only
Published 2012-09-21. Last modified 2026-06-16.