Korean
<< Back
VID 25168
Severity 30
Port 1521, ...
Protocol TCP
Class DB
Detailed Description The ORACLE server on the host system sets REMOTE_OS_AUTHENT to TRUE.
If REMOTE_OS_AUTHENT is set to TRUE, remote clients can access database from trusted remote host without authentication.

* Platforms Affected:
UNIX any version
Linux any version
Microsoft Windows any version
Recommendation Open $Oracle_Home/dbs/SPFILE<SID>.ORA or $Oracle_Home/admin/pfile/init<sid>.ora and add the following.
REMOTE_OS_AUTHENT=FALSE
Related URL (CVE)
Related URL (SecurityFocus)
Related URL (ISS)