Anonymous SQL Execution in Oracle Advanced Support
netspi.com | blog | #web-security | #penetration-testing | #oracle | #unauthenticated | #sql-execution
Summary
An exposed JavaScript file on an Oracle Advanced Support server revealed unauthenticated REST endpoints under /rest/data/ that executed arbitrary SQL, uncovered through external pentest recon.
- Published
- Collected
Skip to content