First published: Thu Nov 08 2007(Updated: )
SQL injection vulnerability in okxLOV.jsp in Oracle E-Business Suite 11 and 12 allows remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: this is probably the same issue as CVE-2007-5527 or CVE-2007-5528, but there are insufficient details to be sure.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle E-Business Suite | =12 | |
Oracle E-Business Suite | =11i |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5766 has been classified as a critical security vulnerability due to its ability to allow remote attackers to execute arbitrary SQL commands.
To fix CVE-2007-5766, users should apply the latest security patches provided by Oracle for E-Business Suite version 11i and 12.
CVE-2007-5766 affects Oracle E-Business Suite versions 11i and 12.
Yes, CVE-2007-5766 may be related to CVE-2007-5527 and CVE-2007-5528, but there is not enough detail to confirm this.
CVE-2007-5766 can be exploited through SQL injection attacks, allowing attackers to manipulate database queries.