SQL Injection Vulnerability in Oracle Application Express of Oracle Database Server
CVE-2020-2971
5.4MEDIUM
What is CVE-2020-2971?
A vulnerability exists in the Oracle Application Express component of Oracle Database Server, allowing low-privileged attackers with SQL Workshop privileges to exploit it. This exploit requires human interaction from a third party, potentially compromising accessible data. Attackers may gain unauthorized access to update, insert, or delete data, as well as read a limited subset of this data, posing significant risks to data integrity and confidentiality.
Affected Version(s)
Application Express 5.1-19.2