Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-34363

Опубликовано: 09 июн. 2023
Источник: nvd
CVSS3: 5.9
EPSS Низкий

Описание

An issue was discovered in Progress DataDirect Connect for ODBC before 08.02.2770 for Oracle. When using Oracle Advanced Security (OAS) encryption, if an error is encountered initializing the encryption object used to encrypt data, the code falls back to a different encryption mechanism that uses an insecure random number generator to generate the private key. It is possible for a well-placed attacker to predict the output of this random number generator, which could lead to an attacker decrypting traffic between the driver and the database server. The vulnerability does not exist if SSL / TLS encryption is used.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:progress:datadirect_odbc_oracle_wire_protocol_driver:*:*:*:*:*:*:*:*
Версия до 08.02.2770 (исключая)

EPSS

Процентиль: 44%
0.00213
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-338
CWE-338

Связанные уязвимости

CVSS3: 5.9
github
больше 2 лет назад

An issue was discovered in Progress DataDirect Connect for ODBC before 08.02.2770 for Oracle. When using Oracle Advanced Security (OAS) encryption, if an error is encountered initializing the encryption object used to encrypt data, the code falls back to a different encryption mechanism that uses an insecure random number generator to generate the private key. It is possible for a well-placed attacker to predict the output of this random number generator, which could lead to an attacker decrypting traffic between the driver and the database server. The vulnerability does not exist if SSL / TLS encryption is used.

EPSS

Процентиль: 44%
0.00213
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-338
CWE-338