Skip to Main Content

APEX

Announcement

For appeals, questions and feedback about Oracle Forums, please email oracle-forums-moderators_us@oracle.com. Technical questions should be asked in the appropriate category. Thank you!

Interactive Report SQL injection

User_V2S5GOct 23 2022

I was pen-testing an apex application and while fuzzing the Interactive Report widget I received an sql error message, "Invalid Filter Expression. ORA-00933: SQL command not properly ended." additionally "Invalid Filter Expression. ORA-00907: missing right parenthesis." I asked the developers whether the query was being performed against the database and they said no? Im wondering if anyone in the community has any experience with this issue and whether this is a valid security concern?

error 1 payload: "f01=F+=+A)+OR+1+=+1"
error 2 payload: "f01=F+=+A)+OR+1+=+1+("
true payload: "f01=F+=+A)+OR+1=1+AND+(1=1" --> true

Comments
Post Details
Added on Oct 23 2022
2 comments
648 views