Vulnerability record · CVE-2012-1675 · published 8 May 2012
CVE-2012-1675: Oracle TNS Listener remote database registration hijack (TNS Poison)
Oracle · Database Server
The Oracle TNS Listener in Database 11g (11.1.0.7, 11.2.0.2, 11.2.0.3) and 10g (10.2.0.3, 10.2.0.4, 10.2.0.5), as used in Fusion Middleware, Enterprise Manager and E-Business Suite, permits remote registration of an already-existing database instance or service name. An attacker who registers a duplicate name can then man-in-the-middle database connections and execute arbitrary database commands.
Description
The TNS Listener, as used in Oracle Database 11g 11.1.0.7, 11.2.0.2, and 11.2.0.3, and 10g 10.2.0.3, 10.2.0.4, and 10.2.0.5, as used in Oracle Fusion Middleware, Enterprise Manager, E-Business Suite, and possibly other products, allows remote attackers to execute arbitrary database commands by performing a remote registration of a database (1) instance or (2) service name that already exists, then conducting a man-in-the-middle (MITM) attack to hijack database connections, aka "TNS Poison."
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityNetwork-reachable with no authentication required, arbitrary command execution impact, and very high EPSS despite absence from KEV.
What it is
The Oracle TNS Listener in Database 11g (11.1.0.7, 11.2.0.2, 11.2.0.3) and 10g (10.2.0.3, 10.2.0.4, 10.2.0.5), as used in Fusion Middleware, Enterprise Manager and E-Business Suite, permits remote registration of an already-existing database instance or service name. An attacker who registers a duplicate name can then man-in-the-middle database connections and execute arbitrary database commands.
Impact
An attacker can hijack database connections and execute arbitrary database commands, exposing or altering data and potentially compromising the database and connected applications.
Attack surface
Reached over the network via the TNS Listener; the CVSS vector AV:N/AC:L/Au:N indicates no authentication is required. The MITM step implies the attacker must be positioned to intercept client-to-listener traffic.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.774, 99.5th percentile) and multiple references are tagged Exploit, indicating public exploit material exists.
What to do
- Apply the Oracle vendor fix referenced in the Oracle security alert for CVE-2012-1675 (patch first).
- Enable TNS Listener valid node checking / registration restrictions so only authorized hosts can register instance or service names.
- Restrict network access to the listener port to trusted database clients and segments.
- Use encrypted and integrity-protected database connections to make MITM hijacking harder.
- Monitor and remove unexpected or duplicate service/instance registrations on the listener.
Detection
- Audit listener logs and lsnrctl services output for unexpected or duplicate instance/service registrations.
- Alert on new or anomalous hosts registering services with the TNS Listener.
- Monitor for connection redirection or session anomalies consistent with MITM hijacking.
- Correlate listener registration events with known authorized client IP ranges.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1675 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1675), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.