The Oracle database component in Sun Management Center (Sun MC) 3.6.1, 3.6, and 3.5 Update 1 has a default account, which allows remote attackers to obtain database access and execute arbitrary code.
| Software | From | Fixed in |
|---|---|---|
| sun / management+center | 3.5_update_1 | 3.5_update_1.x |
| sun / management+center | 3.6 | 3.6.x |
| sun / management+center | 3.6.1 | 3.6.1.x |