Vulnerability Description
Unspecified vulnerability in Oracle Application Express (formerly Oracle HTML DB) 2.2.0.00.32 up to 3.0.0.00.20 allows developers to have an unknown impact via unknown attack vectors, aka APEX01. NOTE: a reliable researcher states that this is SQL injection in the wwv_flow_security.check_db_password function due to insufficient checks for '"' characters.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Apex | <= 3.0.0.00.20 |
References
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&obje
- http://secunia.com/advisories/26114Vendor Advisory
- http://secunia.com/advisories/26166
- http://securityreason.com/securityalert/2901
- http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_July_2
- http://www.oracle.com/technetwork/topics/security/cpujul2007-087014.html
- http://www.red-database-security.com/advisory/oracle_apex_sql_injection_check_db
- http://www.red-database-security.com/advisory/oracle_cpu_jul_2007.html
- http://www.securityfocus.com/archive/1/474002/100/0/threaded
- http://www.securitytracker.com/id?1018415
- http://www.us-cert.gov/cas/techalerts/TA07-200A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2007/2562
- http://www.vupen.com/english/advisories/2007/2635
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35490
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35499
FAQ
What is CVE-2007-3860?
CVE-2007-3860 is a vulnerability with a CVSS score of 7.5 (HIGH). Unspecified vulnerability in Oracle Application Express (formerly Oracle HTML DB) 2.2.0.00.32 up to 3.0.0.00.20 allows developers to have an unknown impact via unknown attack vectors, aka APEX01. NOT...
How severe is CVE-2007-3860?
CVE-2007-3860 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-3860?
Check the references section above for vendor advisories and patch information. Affected products include: Oracle Apex.