Vulnerabilities > CVE-2004-0543 - SQL Injection vulnerability in Oracle Applications and E-Business Suite
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Multiple SQL injection vulnerabilities in Oracle Applications 11.0 and Oracle E-Business Suite 11.5.1 through 11.5.8 allow remote attackers to execute arbitrary SQL procedures and queries.
Vulnerable Configurations
References
- http://archives.neohapsis.com/archives/vulnwatch/2004-q2/0032.html
- http://marc.info/?l=bugtraq&m=108638417302229&w=2
- http://otn.oracle.com/deploy/security/pdf/2004alert67.pdf
- http://www.ciac.org/ciac/bulletins/o-153.shtml
- http://www.integrigy.com/alerts/OraAppsSQLInjection.htm
- http://www.kb.cert.org/vuls/id/961579
- http://www.securityfocus.com/bid/10465
- http://www.us-cert.gov/cas/techalerts/TA04-160A.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16324