Allround Automations PL/SQL Developer 11 before 11.0.6 relies on unverified HTTP data for updates, which allows man-in-the-middle attackers to execute arbitrary code by modifying fields in the client-server data stream.
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Pl/sql_developer | Allroundautomations | 11.0 (including) | 11.0 (including) |
Pl/sql_developer | Allroundautomations | 11.0.1 (including) | 11.0.1 (including) |
Pl/sql_developer | Allroundautomations | 11.0.2 (including) | 11.0.2 (including) |
Pl/sql_developer | Allroundautomations | 11.0.3 (including) | 11.0.3 (including) |
Pl/sql_developer | Allroundautomations | 11.0.4 (including) | 11.0.4 (including) |
Pl/sql_developer | Allroundautomations | 11.0.5 (including) | 11.0.5 (including) |