ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Oracle Applications vulnerable to Web attack

Ingrid Marson ZDNet.co.uk

Published: 10 Jun 2004 14:25 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Oracle Corporation has announced a security flaw in Oracle Applications 11i that allows an attacker to carry out database functions through a company's Web site.

The flaw, which is categorised at the highest severity level, can be exploited with little specialised knowledge and has no work-around, according to the security alert sent out by Oracle. Oracle says the patch should be applied immediately.

The flaw, discovered by security firm Integrigy Corporation, is known as an SQL Injection vulnerability. It allows an attacker to manipulate the database by putting SQL code into Web page input fields. Customers with Internet-facing application servers are most vulnerable because they can be attacked remotely by anyone who has a browser.

Oracle Applications, also called Oracle E-business suite, is a set of applications and modules that enables an organisation to carry out various business functions, including financial management, human resources, and inventory management using a single database model.

Oracle Applications 11.5.1 to 11.5.8 are affected, as are all releases of Oracle Applications 11.0. Releases 11.5.9 and later are not affected. Oracle has provided a patch for the security alert.

Oracle UK declined to comment on this security flaw and was unable to provide figures for the current number of users of Oracle Applications in the UK.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
54 out of 118 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:



Related Jobs

Embedded C - Worcester - Top Automotive company - Company expansion

If yes, then carry on reading. So please if you have these skill sets and you want to be part of a heavily expanding corporation then apply now with ...

Test / Integration Analyst

CORPORATION. COPYRIGHT 2008 ELECTRONIC DATA SYSTEMS CORPORATION. Functions - Ability to design, test, and validate specialized business and technical ...

DBA - SQL Server 2005 - London, South East

Carry out such tasks as tuning the file structure and organisation, scheduling index rebuilds, and identifying any hardware performance bottlenecks. ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Biometric devices. Do you need one?

When saying “biometrics” I am not thinking about law enforcement, AFIS systems, national ID and visa projects. I first think about personal solutions that will make my life easier.... More

1 comment

Barracuda launches counter-suit agains...

Court cases are never pleasant or simple. The ongoing battle between security companies Trend Micro and Barracuda Networks took a new twist on Wednesday, when Barracuda launched a counter-suit... More

Post a comment

Mobile Speed Demon: Wireless Surpasses...

Mobile Speed Demon: Wireless Surpasses Landline Author: Eric Everson, Founder MyMobiSafe.com As I look around my house and throughout my network of friends, I instantly realize... More

Post a comment