PT-2000-2015 · Oracle · Oracle Internet Application Server

Published

2000-12-31

·

Updated

2008-09-10

·

CVE-2000-1236

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Oracle Internet Application Server (IAS) versions 3.0.7 and earlier
Description A SQL injection issue allows remote attackers to execute arbitrary SQL commands via the query string of the URL.
Recommendations For Oracle Internet Application Server (IAS) versions 3.0.7 and earlier, update to a version later than 3.0.7 to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2000-1236

Affected Products

Oracle Internet Application Server