CVE-2016-2346
25.04.2016, 18:59
Allround Automations PL/SQL Developer 11 before 11.0.6 relies on unverified HTTP data for updates, which allows man-in-the-middle attackers to execute arbitrary code by modifying fields in the client-server data stream.Enginsight
Vendor | Product | Version |
---|---|---|
allroundautomations | pl\/sql_developer | 11.0 |
allroundautomations | pl\/sql_developer | 11.0.1 |
allroundautomations | pl\/sql_developer | 11.0.2 |
allroundautomations | pl\/sql_developer | 11.0.3 |
allroundautomations | pl\/sql_developer | 11.0.4 |
allroundautomations | pl\/sql_developer | 11.0.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration