SQL Injection Vulnerability in Oracle Application Express by Oracle
CVE-2020-2972
5.4MEDIUM
Summary
The vulnerability in Oracle Application Express allows attackers with SQL Workshop privileges to manipulate data through SQL injection. This occurs via network access through HTTP, requiring human interaction from the target user to exploit effectively. While primarily affecting Oracle Application Express, successful exploitation can lead to unauthorized changes to data, including updates, inserts, and deletions, along with unauthorized read access to sensitive information. As such, the impact extends beyond the application itself, potentially affecting associated products.
Affected Version(s)
Application Express 5.1-19.2
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved