logo

Oracle EBS Security Flaw: Pre-Auth SQLi Explained

ID: bf8184f2-412f-5454-8630-75b47745e063

STIX ID: report--bf8184f2-412f-5454-8630-75b47745e063

Feed Name: NCC Research

Threat Score
72/100

Date Published: 2025-12-02

Date Updated: 2026-08-01

...
...

Oracle E-Business Suite (multiple 11.x and 12.x versions) was disclosed as vulnerable to pre-auth UNION-based SQL injection (CVE-2014-6583) that could be exploited to gain APPS (DBA) privileges; the issue was rated Critical, disclosed in January 2015, and a patch was released in Oracle's January 2015 CPU.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.