My FAQ,最新最全的IT技术FAQ
最新100篇 | 推荐100篇 | 专题100篇 | 排行榜 | 搜索 | 在线API文档
首 页 | 程序开发 | 操作系统 | 软件应用 | 图形图象 | 网络应用 | 精文荟萃 | 教育认证 | 未整理篇 | 技术讨论
  当前位置: > 程序开发 > 编程语言 > Java > 数据库
Security Flaw Discovered in Oracle E-Business Suite @ JDJ
作者:未知 时间:2005-08-10 22:54 出处:Java频道 责编:My FAQ
              摘要:Security Flaw Discovered in Oracle E-Business Suite @ JDJ
An unauthenticated user with browser access to a Web server hosting the E ­Business Suite application and specialized knowledge can exploit vulnerabilities, says a top-level security alert from Oracle this week.

Oracle Security Alert 67 declares that, without a patch issued by Oracle, Oracle E-Business Suite 11i and Oracle Applications 11.0 packages are subject to multiple SQL injection flaws that could be used to manipulate database entries.

Oracle shops with Internet-facing application servers are particularly at risk, says the security tools firm Integrigy, which describes the vulnerabilities as follows:

"Integrigy has discovered multiple SQL injection vulnerabilities in almost all supported versions of Oracle Applications (11.0 and 11i).

Because Oracle Applications 11i installs code for all product modules, all Oracle Applications 11i customers are vulnerable to these SQL injection issues.

A SQL injection vulnerability allows an attacker to execute SQL statements or database functions by inserting SQL code fragments into input fields of a web page. Due to the design of Oracle Applications, a SQL injection attack can easily and effectively compromise the entire database and application."
Oracle has released a patch for Oracle Applications 11.0 and the Oracle E-Business Suite 11i to correct these vulnerabilities.
 
首页 | 投资与合作 | 服务条款 | 隐私政策 | 收藏本站 | 设为首页 | 新用户注册 | 免责声明 | 使用帮助
Copyright ©2005-2008 myfaq.com.cn All rights reserved. www.myfaq.com.cn 版权所有