CVE-2012-1675

high
Published 2012-05-08 · Modified 2026-04-29
CVSS v3
CVSS v2
7.5
VIR risk
7.5

Description

The TNS Listener, as used in Oracle Database 11g 11.1.0.7, 11.2.0.2, and 11.2.0.3, and 10g 10.2.0.3, 10.2.0.4, and 10.2.0.5, as used in Oracle Fusion Middleware, Enterprise Manager, E-Business Suite, and possibly other products, allows remote attackers to execute arbitrary database commands by performing a remote registration of a database (1) instance or (2) service name that already exists, then conducting a man-in-the-middle (MITM) attack to hijack database connections, aka "TNS Poison."

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert_us@oracle.com — https://blogs.oracle.com/security/entry/security_alert_for_cve_2012

vendor Authored 2026-05-27

Vendor advisory: secalert_us@oracle.com — http://www.oracle.com/technetwork/topics/security/alert-cve-2012-1675-1608180.html

Application impact

VendorProductVersionsFixed
oracle oracledatabase_server10.2.0.3
oracle oracledatabase_server10.2.0.4
oracle oracledatabase_server10.2.0.5
oracle oracledatabase_server11.1.0.7
oracle oracledatabase_server11.2.0.2
oracle oracledatabase_server11.2.0.3
oracle oracledatabase_server11.2.0.4

References

CWEs

CWE-264

Verify integrity in audit chain (admin only). AS-IS.