CVE-2023-46806: SQL Injection
An SQL Injection vulnerability in a web component of EPMM versions before 12.1.0.0 allows an authenticated user with appropriate privilege to access or modify data in the underlying database.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-46806?
CVE-2023-46806 is classified as a high-severity SQL Injection vulnerability.
How do I fix CVE-2023-46806?
To fix CVE-2023-46806, upgrade your Oracle Enterprise Performance Management Management software to version 12.1.0.0 or later.
Who is affected by CVE-2023-46806?
CVE-2023-46806 affects users of Oracle Enterprise Performance Management Management versions prior to 12.1.0.0.
What type of attack does CVE-2023-46806 allow?
CVE-2023-46806 allows an authenticated user to execute SQL Injection attacks, enabling unauthorized access or modification of the database.
What systems are impacted by CVE-2023-46806?
CVE-2023-46806 impacts web components within the specified versions of Oracle Enterprise Performance Management Management software.