Oracle Default SID

This script is Copyright (C) 2006-2014 Tenable Network Security, Inc.


Synopsis :

It is possible to identify databases on the remote host.

Description :

The remote Oracle database server either contains one or more
databases that use well-known System Identifiers (SIDs) or supports
the 'services' command as a means of listing available SIDs on the
affected system.

Since an Oracle SID serves to uniquely identify a particular database
on a given host and is required when connecting to an Oracle database,
an attacker can leverage these SIDs to attempt to access databases on
the remote host.

Solution :

Change any SIDs that are identified.

Risk factor :

None

Family: Databases

Nessus Plugin ID: 22074 ()

Bugtraq ID:

CVE ID: