CVE-2002-1631SQL Injection in Oracle Application Server

3 documents3 sources
Severity
7.5HIGHNVD
EPSS
5.9%
top 9.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 31
Latest updateApr 30

Description

SQL injection vulnerability in the query.xsql sample page in Oracle 9i Application Server (9iAS) allows remote attackers to execute arbitrary code via the sql parameter.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

NVDoracle/application_server5 versions+4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-m54v-h5r2-5m3r: SQL injection vulnerability in the query2022-04-30
CVEList
CVE-2002-1631: SQL injection vulnerability in the query2005-03-26