Skip to Main Content

APEX

Announcement

For appeals, questions and feedback about Oracle Forums, please email oracle-forums-moderators_us@oracle.com. Technical questions should be asked in the appropriate category. Thank you!

Apex SQL injection

user13304539Jun 15 2015 — edited Jun 15 2015

Dear ,

I have an apex application that working well and all functionality working fine also ,security team at my company raised an SQL injection risk issue regarding this application .

This issue raised at any DML action done through this application .

This issue can be reproduce by use any incept proxy (ex. Burp suite) and once I make any change and perform submit action  during that I can incept the data and make any change I want before re-forwarding it to database .

I used checksum state protection on page and session level but I still have the same issue .

Do you have any idea how I can permanently stop this risk ?

please find the attached screenshots .

Comments
Locked Post
New comments cannot be posted to this locked post.
Post Details
Locked on Jul 13 2015
Added on Jun 15 2015
7 comments
509 views