// For flags

CVE-2007-5766

Oracle E-Business Suite SQL Injection Vulnerability

Severity Score

7.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

SQL injection vulnerability in okxLOV.jsp in Oracle E-Business Suite 11 and 12 allows remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: this is probably the same issue as CVE-2007-5527 or CVE-2007-5528, but there are insufficient details to be sure.

Vulnerabilidad de inyección SQL en okxLOV.jsp de Oracle E-Business Suite 11 y 12 permite a atacantes remotos ejecutar comandos sql de su elección mediante vectores desconocidos. NOTA: este es probablemente el mismo asunto que CVE-2007-5527 o CVE-2007-5528, pero no hay detalles suficientes como para estar seguros.

This vulnerability allows remote attackers to inject arbitrary SQL on vulnerable installations of Oracle E-Business Suite. Authentication is not required to exploit this vulnerability.
The specific flaw exists in the okxLOV.jsp page in the Administration console. This page allows an attacker to specify arguments to a WHERE SQL command without sanitation, allowing for arbitrary SQL injection in the context of the APPS user.

*Credits: Joxean Koret
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-10-31 CVE Reserved
  • 2007-10-31 CVE Published
  • 2024-08-04 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Oracle
Search vendor "Oracle"
E-business Suite
Search vendor "Oracle" for product "E-business Suite"
11i
Search vendor "Oracle" for product "E-business Suite" and version "11i"
-
Affected
Oracle
Search vendor "Oracle"
E-business Suite
Search vendor "Oracle" for product "E-business Suite"
12
Search vendor "Oracle" for product "E-business Suite" and version "12"
-
Affected