- Oracle9i Application Server Portal Release 1, v 3.0.9.8.5 and earlier
- Oracle9i Application Server Portal Release 2, v 9.0.2.3.0 and earlier
Portal version 9.0.2.6 and onwards are not vulnerable.
Stored packages and procedures can be accessed using PL/SQL through Oracle's Application Server's Portal module. Many of the PL/SQL packages and procedures are vulnerable to SQL Injection. An unauthenticated user can launch a SQL Injection attack and gain unauthorized access to data in Oracle9i Application Server.
Impact
A malicious user with HTTP access can gain access to all data in the database from the Internet or corporate network. The malicious user can also execute unauthorized queries to compromise data integrity and affect database server performance.