How do you handle CVE-2012-1675
Hi all!
Not very funny in these days...
I've read several articles about the altert CVE-2012-1675 mentioned here http://www.oracle.com/technetwork/topics/security/alert-cve-2012-1675-1608180.html
Now I need to think about how we should solve this problem on hundreds of servers.
I've found the notes about using COST:
https://support.oracle.com/CSP/main/article?cmd=show&type=NOT&id=1453883.1 (standalone)
https://support.oracle.com/CSP/main/article?cmd=show&type=NOT&id=1340831.1 (RAC)
For the first one (standalone), method 1 recommends setting SECURE_REGISTER_<listener_name>=(TCP) in the listener.ora. But fix for bug 12880299