Oracle Database Protection Mechanism Bypass
Posted by deepcore on December 14, 2021 – 4:56 am
Due to insecure fallback behavior, a man-in-the-middle attacker can bypass NNE’s protection against man-in-the-middle attacks and hijack authenticated connections. In some configurations, a full man-in-the-middle attack is possible. Oracle Database versions 19c, 12.2.0.1, and 12.1.0.2 are affected.
Post a reply
You must be logged in to post a comment.