DB: Oracle Insecure TNS Listener Configuration

This signature detects an Oracle Database instance where the listener security options have been disabled, enabling database access for any connection (including attackers). Servers triggering this signature should be reviewed by a qualified Oracle DBA for security concerns.

Extended Description

A denial of service vulnerability exists in Oracle 8i. An attacker connecting to the host and sending a malformed SQLNet (Type-1) connection request, could cause the host to stop responding.

Affected Products

Oracle oracle8

Short Name
DB:ORACLE:INSECURE-TNS-LISTENER
Severity
Minor
Recommended
False
Recommended Action
None
Category
DB
Keywords
CVE-2001-0498 Configuration Insecure Listener Oracle TNS bid:2940
Release Date
09/16/2004
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
Port
TCP/1521
False Positive
Unknown
Vendors

Oracle

CVSS Score

5.0

Found a potential security threat?