Multiple SQL-injection vulnerabilities in Oracle 9i Application Server and RDBMS

Multiple SQL-injection vulnerabilities in Application Server and RDBMS can result in remote compromise of the vulnerable server.

Ken Pfeil

November 5, 2003

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported November 5, 2003, by NGSSoftware.

 

 

VERSIONS AFFECTED

 

  • Oracle9i Application Server Releases 1 and 2

  • Oracle Relational Database Management System (RDBMS)

 

DESCRIPTION

 

Multiple SQL-injection vulnerabilities in Application Server and RDBMS can result in remote compromise of the vulnerable server. Many of the Procedural Level (PL)/SQL packages and procedures that Application Server uses are vulnerable to SQL injection. An unauthenticated attacker can exploit these vulnerabilities to gain access from the Internet to all data in the database.

 

VENDOR RESPONSE

 

Oracle has released analert regarding this vulnerability.

 

CREDIT
 

Discovered byNGSSoftware.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like