RULE(RULE ID:1705157)

Rule General Information
Release Date: 2020-09-22
Rule Name: Oracle TNS Listener SID Unauthorized Access Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: A vulnerability that allows an attacker to poison data processed by a remote "TNS Listener" component without providing a user name/password. An attacker can exploit this vulnerability to redirect data from a legitimate TNS Listener component of a database server to a system controlled by the attacker, resulting in control of a remote component's database instance, resulting in a man-in-the-middle attack, session hijacking, or denial of service attack between the component and the legitimate database.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.