Synced 30 Sept 2026 23:45 UTC Account
← All products

CVE-2004-1366

MEDIUM severity · CVSS 4.6 · CWE-255
4.6CVSS MEDIUM

Summary

Oracle 10g Database Server stores the password for the SYSMAN account in cleartext in the world-readable emoms.properties file, which could allow local users to gain DBA privileges.

Impact & exploitability

Attack vectorLocal
Attack complexityLow
Privileges required—
User interaction—
Confidentiality impact—
Integrity impact—
Availability impact—
Exploit probability (EPSS)15%

AV:L/AC:L/Au:N/C:P/I:P/A:P

Affected products we track (1)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.

Official patch: http://www.ngssoftware.com/advisories/oracle23122004D.txt ↗