您的位置:首页 > 数据库 > Oracle

Security Flaw Discovered in Oracle E-Business Suite @ JDJ

2008-05-01 06:14 477 查看
An unauthenticated user with browser access to a Web server hosting the E ­Business Suite application and specialized knowledge can exploit vulnerabilities, says a top-level Oracle.com/deploy/Security/pdf/2004alert67.pdf" />Security alert from Oracle this week.
Oracle Security Alert 67 declares that, without a patch issued by Oracle, Oracle E-Business Suite 11i and Oracle Applications 11.0 packages are subject to multiple SQL injection Flaws that could be used to manipulate database entries.
Oracle shops with internet-facing application servers are particularly at risk, says the Security tools firm integrigy.com/alerts/oraappssqlinjection.htm" />integrigy, which describes the vulnerabilities as follows:
"integrigy has discovered multiple SQL injection vulnerabilities in almost all supported versions of Oracle Applications (11.0 and 11i).
Because Oracle Applications 11i installs code for all product modules, all Oracle Applications 11i customers are vulnerable to these SQL injection issues.
A SQL injection vulnerability allows an attacker to execute SQL statements or database functions by inserting SQL code fragments into input fields of a web page. Due to the design of Oracle Applications, a SQL injection attack can easily and effectively compromise the entire database and application." Oracle has released a patch for Oracle Applications 11.0 and the Oracle E-Business Suite 11i to correct these vulnerab
内容来自用户分享和网络整理,不保证内容的准确性,如有侵权内容,可联系管理员处理 点击这里给我发消息
标签: 
相关文章推荐