← Vulnerability feed

Vulnerability record · CVE-2012-1675 · published 8 May 2012

CVE-2012-1675: Oracle TNS Listener remote database registration hijack (TNS Poison)

Oracle · Database Server

The Oracle TNS Listener in Database 11g (11.1.0.7, 11.2.0.2, 11.2.0.3) and 10g (10.2.0.3, 10.2.0.4, 10.2.0.5), as used in Fusion Middleware, Enterprise Manager and E-Business Suite, permits remote registration of an already-existing database instance or service name. An attacker who registers a duplicate name can then man-in-the-middle database connections and execute arbitrary database commands.

7.5 CVSS 2.0 High EPSS 77% · top 0.5% CWE-264 · Permissions and access controls
7.5CVSS 2.0 base score
77%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
20References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

The TNS Listener, as used in Oracle Database 11g 11.1.0.7, 11.2.0.2, and 11.2.0.3, and 10g 10.2.0.3, 10.2.0.4, and 10.2.0.5, as used in Oracle Fusion Middleware, Enterprise Manager, E-Business Suite, and possibly other products, allows remote attackers to execute arbitrary database commands by performing a remote registration of a database (1) instance or (2) service name that already exists, then conducting a man-in-the-middle (MITM) attack to hijack database connections, aka "TNS Poison."

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityNetwork-reachable with no authentication required, arbitrary command execution impact, and very high EPSS despite absence from KEV.

What it is

The Oracle TNS Listener in Database 11g (11.1.0.7, 11.2.0.2, 11.2.0.3) and 10g (10.2.0.3, 10.2.0.4, 10.2.0.5), as used in Fusion Middleware, Enterprise Manager and E-Business Suite, permits remote registration of an already-existing database instance or service name. An attacker who registers a duplicate name can then man-in-the-middle database connections and execute arbitrary database commands.

Impact

An attacker can hijack database connections and execute arbitrary database commands, exposing or altering data and potentially compromising the database and connected applications.

Attack surface

Reached over the network via the TNS Listener; the CVSS vector AV:N/AC:L/Au:N indicates no authentication is required. The MITM step implies the attacker must be positioned to intercept client-to-listener traffic.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.774, 99.5th percentile) and multiple references are tagged Exploit, indicating public exploit material exists.

What to do

  • Apply the Oracle vendor fix referenced in the Oracle security alert for CVE-2012-1675 (patch first).
  • Enable TNS Listener valid node checking / registration restrictions so only authorized hosts can register instance or service names.
  • Restrict network access to the listener port to trusted database clients and segments.
  • Use encrypted and integrity-protected database connections to make MITM hijacking harder.
  • Monitor and remove unexpected or duplicate service/instance registrations on the listener.

Detection

  • Audit listener logs and lsnrctl services output for unexpected or duplicate instance/service registrations.
  • Alert on new or anomalous hosts registering services with the TNS Listener.
  • Monitor for connection redirection or session anomalies consistent with MITM hijacking.
  • Correlate listener registration events with known authorized client IP ranges.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-security-announce/2012-06/msg00018.html Mailing ListThird Party Advisory
http://seclists.org/fulldisclosure/2012/Apr/204 ExploitMailing ListThird Party Advisory
http://seclists.org/fulldisclosure/2012/Apr/343 Mailing ListThird Party Advisory
http://www.kb.cert.org/vuls/id/359816 Third Party AdvisoryUS Government Resource
http://www.mandriva.com/security/advisories?name=MDVSA-2013:150 Third Party Advisory
http://www.oracle.com/technetwork/topics/security/alert-cve-2012-1675-1608180.html Vendor Advisory
http://www.securityfocus.com/bid/53308 ExploitThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1027000 Third Party AdvisoryVDB Entry
https://blogs.oracle.com/security/entry/security_alert_for_cve_2012 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/75303 VDB Entry
http://lists.opensuse.org/opensuse-security-announce/2012-06/msg00018.html Mailing ListThird Party Advisory
http://seclists.org/fulldisclosure/2012/Apr/204 ExploitMailing ListThird Party Advisory
http://seclists.org/fulldisclosure/2012/Apr/343 Mailing ListThird Party Advisory
http://www.kb.cert.org/vuls/id/359816 Third Party AdvisoryUS Government Resource
http://www.mandriva.com/security/advisories?name=MDVSA-2013:150 Third Party Advisory
http://www.oracle.com/technetwork/topics/security/alert-cve-2012-1675-1608180.html Vendor Advisory
http://www.securityfocus.com/bid/53308 ExploitThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1027000 Third Party AdvisoryVDB Entry
https://blogs.oracle.com/security/entry/security_alert_for_cve_2012 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/75303 VDB Entry

Track CVE-2012-1675 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2020-1953Apache commons configuration vulnerabilityApache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes…EPSS 6.8%10.0CVE-2015-4863Oracle database server vulnerabilityUnspecified vulnerability in the Portable Clusterware component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote attackers to…EPSS 3.1%10.0CVE-2013-1534Oracle database server vulnerabilityUnspecified vulnerability in the Workload Manager component in Oracle Database Server 11.2.0.2 and 11.2.0.3, when used in RAC configurations, allows …EPSS 3.7%10.0CVE-2010-0071Oracle database server vulnerabilityUnspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers t…EPSS 9.8%10.0CVE-2009-1979Oracle Database Network Authentication component remote code execution riskAn unspecified flaw in the Network Authentication component of Oracle Database 10.1.0.5 and 10.2.0.4 lets remote attackers affect confidentiality, in…EPSS 76%analysed10.0CVE-2009-1985Oracle database server vulnerabilityUnspecified vulnerability in the Network Authentication component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.4 allows remote attacke…EPSS 5.4%10.0CVE-2009-1992Oracle database server vulnerabilityUnspecified vulnerability in the Core RDBMS component in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.4 allows remote attackers to affect confidenti…EPSS 4.2%10.0CVE-2008-1818Oracle database server vulnerabilityUnspecified vulnerability in the Authentication component in Oracle Database 11.1.0.6 has unknown impact and remote attack vectors, aka DB08.EPSS 3.0%

Source: NIST National Vulnerability Database (record CVE-2012-1675), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.