CVE-2007-3860 Information

Description

Unspecified vulnerability in Oracle Application Express (formerly Oracle HTML DB) 2.2.0.00.32 up to 3.0.0.00.20 allows developers to have an unknown impact via unknown attack vectors aka APEX01. NOTE: a reliable researcher states that this is SQL injection in the wwv_flow_security.check_db_password function due to insufficient checks for ‘' characters.

Reference

http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c00727143 http://secunia.com/advisories/26114 http://secunia.com/advisories/26166 http://securityreason.com/securityalert/2901 http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_July_2007_Analysis.pdf http://www.oracle.com/technetwork/topics/security/cpujul2007-087014.html http://www.red-database-security.com/advisory/oracle_apex_sql_injection_check_db_password.html http://www.red-database-security.com/advisory/oracle_cpu_jul_2007.html http://www.securityfocus.com/archive/1/474002/100/0/threaded http://www.securitytracker.com/id?1018415 http://www.us-cert.gov/cas/techalerts/TA07-200A.html http://www.vupen.com/english/advisories/2007/2562 http://www.vupen.com/english/advisories/2007/2635 https://exchange.xforce.ibmcloud.com/vulnerabilities/35490 https://exchange.xforce.ibmcloud.com/vulnerabilities/35499

Share on: