vendor:
APEX
by:
Alexander Kornbrust
7.5
CVSS
HIGH
Password Disclosure
255
CWE
Product Name: APEX
Affected Version From: APEX 3.0 (optional component of 11.1.0.7 installation)
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2009-0981
CPE: a:oracle:application_express:3.0
Platforms Tested:
2009
Unprivileged DB users can see APEX password hashes in FLOWS_030000.WWV_FLOW_USER [CVE-2009-0981]
Unprivileged database users can see APEX password hashes in FLOWS_030000.WWV_FLOW_USER.
Mitigation:
Unknown