First published: Wed Jan 18 2006(Updated: )
Unspecified vulnerability in the Transparent Data Encryption (TDE) Wallet component of Oracle Database server 10.2.0.1 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB27. NOTE: Oracle has not disputed a reliable researcher report that TDA stores the master key without encryption, which allows local users to obtain the key via the SGA.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Database | =10.2.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0270 has an unspecified severity level as its impact and attack vectors are not clearly defined.
There is no specific fix provided for CVE-2006-0270; it is recommended to apply the latest security patches from Oracle.
CVE-2006-0270 affects Oracle Database Server version 10.2.0.1.
The vulnerability in CVE-2006-0270 lies within the Transparent Data Encryption (TDE) Wallet component.
CVE-2006-0270 is characterized by its unspecified impact and potential attack vectors related to key management.