SQL Injection (CWE-89)CVSS 10€1,000 PRO
Unauthenticated PL/SQL Injection via a Package-Name Parameter (Oracle, error-based)
A WebSSO path-normalization bypass (static-asset extension + %2e%2e) exposed a legacy connector's executor servlet, which concatenates a request parameter verbatim as a PL/SQL package name → unauthenticated arbitrary PL/SQL execution on production Oracle (error-based cross-schema read + reversible write proof).
1. Summary
An internal back-office web application in production ran on a legacy Oracle backend, fronted by a WebSSO (access-management proxy) and a WAF. Two flaws were chained into unauthenticated arbitrary PL/SQL execution:
- Authorization bypass reaching an executor endpoint. A legacy Java "connector" exposes executor servlets that run PL/SQL. They become reachable without authentication through a path-normalization gap: