CVE-2006-1037: SQL Injection
SQL injection vulnerability in the Oracle Diagnostics module 2.2 and earlier allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1037?
CVE-2006-1037 is a high severity SQL injection vulnerability that allows attackers to execute arbitrary SQL commands.
How do I fix CVE-2006-1037?
To mitigate CVE-2006-1037, you should update to the latest version of Oracle E-Business Suite or Oracle Diagnostics that addresses this vulnerability.
Which versions of Oracle are affected by CVE-2006-1037?
CVE-2006-1037 affects Oracle E-Business Suite versions 11.5.3 through 11.5.10.2 and Oracle Diagnostics versions 2.0 through 2.2.
What can attackers achieve with CVE-2006-1037?
Attackers exploiting CVE-2006-1037 can gain unauthorized access to the database and execute malicious SQL commands.
Is CVE-2006-1037 a remote vulnerability?
Yes, CVE-2006-1037 is a remote vulnerability that allows attackers to exploit it over the network without needing physical access.