E20-0sqh1
CVSS:
6.5 (AV:N/AC:L/Au:S/C:P/I:P/A:P)
False Positive:
t
Variants:
1
Year:
2019
Description
A SQL injection vulnerability exists in the Work in Progress component of Oracle E-Business Suite. A SQL query may be bundled in a FndMessageRequest object sent via the Thin Client Framework protocol over HTTP, which is later processed in the public Vector fetchMessages method located in oracle/apps/wip/gantt/components/server/database/MessageFetcher.class. By exploiting this flaw, a remote unauthenticated attacker may execute arbitrary database queries, such as altering user passwords.
CVE
References
MSB
BID
ExploitDB
Secunia
Security Tracker
Metasploit
ZDI
OSVDB
{}