Oracle 10g Database Server stores the password for the SYSMAN account in cleartext in the world-readable emoms.properties file, which could allow local users to gain DBA privileges.Referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/18661http://www.securityfocus.com/archive/1/385323http://www.kb.cert.org/vuls/id/316206http://www.us-cert.gov/cas/techalerts/TA04-245A.htmlhttp://www.ngssoftware.com/advisories/oracle23122004D.txthttp://www.securityfocus.com/bid/10871http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdfhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1