Vulnerability Name: | CCN-21348 | ||||||
Published: | 2005-07-12 | ||||||
Updated: | 2005-07-12 | ||||||
Summary: | Oracle E-Business Suite is vulnerable to SQL injection. A remote attacker could send a specially-crafted URL containing malicious SQL code in multiple unknown parameters to allow the attacker to obtain sensitive information, and add, modify or delete data in the backend database. An attacker could use this vulnerability to gain DBA privileges on the system. | ||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||
CVSS v2 Severity: | 7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 6.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
| ||||||
Vulnerability Consequences: | Data Manipulation | ||||||
References: | Source: CCN Type: Integrigy Security Advisory July 12, 2005 Multiple High Risk Vulnerabilities in Oracle E-Business Suite 11i Source: CCN Type: Oracle E-Business Suite 11i Web site Oracle E-Business Suite 11i.10 Source: CCN Type: Oracle Critical Patch Update Advisory dated July 2005 Oracle Critical Patch Update - July 2005 Source: XF Type: UNKNOWN ebusiness-suite-multiple-sql-injection(21348) | ||||||
Vulnerable Configuration: | Configuration CCN 1:![]() | ||||||
BACK |