Oracle TDE masterkey in plaintext in SJA
| oracle-sga-masterkey-plaintext (24186) |
Description:
Oracle 10g stores the Transparent Data Encryption (TDE) masterkey in plaintext in the Oracle System Global Area (SJA). A remote authenticated attacker could exploit this vulnerability to obtain the masterkey used for TDE encryption.
Platforms Affected:
- Oracle, Database Server 10.2.0.1 R2
Remedy:
Refer to Oracle Critical Patch Update - January 2006 for patch, upgrade, or suggested workaround information. See References.
Consequences:
Other
References:
- Full-Disclosure Mailing List, Tue Jan 17 2006 - 14:32:55 CST, Oracle Database 10g Rel. 2- Transparent Data Encryption plaintext masterkey in SGA at http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0574.html.
- Oracle Web site, Oracle Critical Patch Update - January 2006 at http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html. (DB27)
- BID-16287: Oracle January Security Update Multiple Vulnerabilities
- CVE-2006-0270: Unspecified vulnerability in the Transparent Data Encryption (TDE) Wallet component of Oracle Database server 10.2.0.1 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB27. NOTE: Oracle has not disputed a reliable researcher report that TDA stores the master key without encryption, which allows local users to obtain the key via the SGA.
- SA18493: Oracle Products Multiple Vulnerabilities and Security Issues
- SA18608: HP Oracle for Openview Multiple Vulnerabilities
- SECTRACK ID: 1015499: Oracle Database and Other Products Have Multiple Unspecified Vulnerabilities With Unspecified Impact
- US-CERT VU#545804: Oracle products contain multiple vulnerabilities
- VUPEN/ADV-2006-0243: Oracle Products Multiple SQL Injection and Security Bypass Vulnerabilities
- VUPEN/ADV-2006-0323: HP Oracle for Openview (OfO) Multiple Remote and Local Vulnerabilities
Reported:
Jan 18, 2006
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
