First published: Mon Nov 03 2003(Updated: )
Multiple SQL injection vulnerabilities in the Portal DB (1) List of Values (LOVs), (2) Forms, (3) Hierarchy, and (4) XML components packages in Oracle Oracle9i Application Server 9.0.2.00 through 3.0.9.8.5 allow remote attackers to execute arbitrary SQL commands via the URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Oracle9i | =9.0.2.2 | |
Oracle Oracle9i | =9.0.2 | |
Oracle Application Server Portal | =9.0.2.3b | |
Oracle Application Server Portal | =3.0.9.8.5 | |
Oracle Application Server Portal | =9.0.2.3 | |
Oracle Application Server Portal | =9.0.2.3a | |
Oracle Oracle9i | =9.0.2.0.0 | |
Oracle Oracle9i | =9.0.2.1 | |
Oracle Oracle9i | =9.0.2.3 | |
Oracle Oracle9i | =9.0.2.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1193 is considered a high severity vulnerability due to its potential for remote exploitation.
To mitigate CVE-2003-1193, apply the latest security patches provided by Oracle for affected versions of Oracle9i Application Server and Portal.
CVE-2003-1193 includes SQL injection vulnerabilities in List of Values, Forms, Hierarchy, and XML components.
CVE-2003-1193 affects users of Oracle Oracle9i Application Server and Oracle Application Server Portal versions listed in the vulnerability.
Yes, CVE-2003-1193 can allow attackers to execute arbitrary SQL commands, potentially leading to data breaches.