Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Anonymous SQL Execution in Oracle Advanced Support

Summary

An exposed JavaScript file on an Oracle Advanced Support server revealed unauthenticated REST endpoints under /rest/data/ that executed arbitrary SQL, uncovered through external pentest recon.
Published
Collected

original ↗