|
Oracle Workspace Manager LT Package SQL Injection Vulnerability
Oracle Workspace Manager is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. Successful exploits allow 'PUBLIC' users to gain 'SYS' privileges; other attacks may also be possible. NOTE: This issue was previously documented in BID 26039 (Oracle October 2007 Critical Patch Update Multiple Vulnerabilities) but has been given its own BID because further technical details are now available. |
|
|
Privacy Statement |