CVE-2015-4846: SQL Injection
Unspecified vulnerability in the Oracle Applications Manager component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote authenticated users to affect confidentiality and integrity via vectors related to SQL Extensions. NOTE: the previous information is from the October 2015 CPU. Oracle has not commented on third-party claims that this issue is a SQL injection vulnerability, which allows remote authenticated users to execute arbitrary SQL commands via a request involving the afamexts.sql SQL extension.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4846?
CVE-2015-4846 is considered to be a moderate severity vulnerability affecting Oracle E-Business Suite.
How do I fix CVE-2015-4846?
To fix CVE-2015-4846, apply the latest Oracle patch provided in the security updates for Oracle E-Business Suite.
Who is affected by CVE-2015-4846?
CVE-2015-4846 affects remote authenticated users of Oracle E-Business Suite versions 11.5.10.2, 12.0.6, 12.1.3, 12.2.3, and 12.2.4.
What types of issues can CVE-2015-4846 cause?
CVE-2015-4846 may impact the confidentiality and integrity of data within the Oracle E-Business Suite.
Is CVE-2015-4846 a SQL injection vulnerability?
CVE-2015-4846 is related to SQL Extensions, which can potentially lead to SQL injection issues.