Allround Automations PL/SQL Developer 11 before 11.0.6 relies on unverified HTTP data for updates, which allows man-in-the-middle attackers to execute arbitrary code by modifying fields in the client-server data stream.
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Pl/sql_developer | Allroundautomations | 11.0 | 11.0 |
Pl/sql_developer | Allroundautomations | 11.0.1 | 11.0.1 |
Pl/sql_developer | Allroundautomations | 11.0.2 | 11.0.2 |
Pl/sql_developer | Allroundautomations | 11.0.3 | 11.0.3 |
Pl/sql_developer | Allroundautomations | 11.0.4 | 11.0.4 |
Pl/sql_developer | Allroundautomations | 11.0.5 | 11.0.5 |