CVE-2023-34363
CVSS 3.1 Score 5.9 of 10 (medium)
Details
Summary
CVE-2023-34363 is a vulnerability affecting Progress DataDirect Connect for ODBC versions prior to 08.02.2770 when used with Oracle and Oracle Advanced Security (OAS) encryption. If an error occurs during encryption object initialization, the software falls back to an insecure random number generator to generate the private key. An attacker in a privileged position could predict the output of this generator, leading to potential decryption of traffic between the driver and the database server. This vulnerability is mitigated if SSL/TLS encryption is used instead.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.