Oracle Applications 11i has a security weakness where passwords are encrypted with keys that can be decrypted, allowing access to any user account. This is due to passwords being encrypted with the APPS database password instead of a strong hash. With access to a production or cloned database, an insider can use published exploit code to decrypt passwords. Most Oracle 11i implementations are vulnerable to some degree unless strong access controls are in place.