SQL Injection Vulnerability in Oracle Application Express by Oracle
CVE-2020-2972
5.4MEDIUM
What is CVE-2020-2972?
The vulnerability in Oracle Application Express allows attackers with SQL Workshop privileges to manipulate data through SQL injection. This occurs via network access through HTTP, requiring human interaction from the target user to exploit effectively. While primarily affecting Oracle Application Express, successful exploitation can lead to unauthorized changes to data, including updates, inserts, and deletions, along with unauthorized read access to sensitive information. As such, the impact extends beyond the application itself, potentially affecting associated products.
Affected Version(s)
Application Express 5.1-19.2