Vulnerabilities > CVE-2013-5795 - Remote Security vulnerability in Oracle products

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
oracle
exploit available
metasploit

Summary

Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 12.2.1, 12.2.2, and 12.2.3 allows remote attackers to affect confidentiality via unknown vectors related to DM Others.

Exploit-Db

descriptionOracle Demantra 12.2.1 - Database Credentials Disclosure. CVE-2013-5795. Webapps exploit for windows platform
idEDB-ID:31995
last seen2016-02-03
modified2014-03-01
published2014-03-01
reporterPortcullis
sourcehttps://www.exploit-db.com/download/31995/
titleOracle Demantra 12.2.1 - Database Credentials Disclosure

Metasploit

descriptionThis module exploits a database credentials leak found in Oracle Demantra 12.2.1 in combination with an authentication bypass. This way an unauthenticated user can retrieve the database name, username and password on any vulnerable machine.
idMSF:AUXILIARY/SCANNER/HTTP/ORACLE_DEMANTRA_DATABASE_CREDENTIALS_LEAK
last seen2020-05-24
modified2019-03-05
published2014-04-07
references
reporterRapid7
sourcehttps://github.com/rapid7/metasploit-framework/blob/master//modules/auxiliary/scanner/http/oracle_demantra_database_credentials_leak.rb
titleOracle Demantra Database Credentials Leak

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/125484/oracledemantra-leak.txt
idPACKETSTORM:125484
last seen2016-12-05
published2014-03-02
reporterOliver Gruskovnjak
sourcehttps://packetstormsecurity.com/files/125484/Oracle-Demantra-12.2.1-Database-Credential-Leak.html
titleOracle Demantra 12.2.1 Database Credential Leak