First published: Mon Sep 19 2005(Updated: )
SQL injection vulnerability in Oracle Reports that use Lexical References allows remote attackers to execute arbitrary SQL commands via the values in the parameter form that appears when the paramform parameter is set to yes.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Reports Developer | =1.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2983 is considered a high severity vulnerability due to the potential for remote attackers to execute arbitrary SQL commands.
To fix CVE-2005-2983, update to a version of Oracle Reports that has patched this SQL injection vulnerability.
CVE-2005-2983 allows attackers to perform SQL injection, potentially leading to unauthorized data access or manipulation.
CVE-2005-2983 affects Oracle Reports version 1.00 that utilizes Lexical References in its configurations.
Yes, CVE-2005-2983 can be exploited by remote attackers without requiring authentication, exposing the application to unauthorized SQL execution.