Oracle Warehouse Builder SQL Injection

Added: 08/01/2011
CVE: CVE-2011-0799
BID: 47431
OSVDB: 71956


Oracle Warehouse Builder (OWB) is an ETL tool produced by Oracle that offers a graphical environment to build, manage and maintain data integration processes in business intelligence systems.


A SQL injection vulnerability exists in Oracle Warehouse Builder versions,, and prior. An authenticated user with the CONNECT privilege may leverage this vulnerability to remotely compromise the server.


Apply the April 2011 Oracle Critical Patch Update.



This exploit has been tested against Oracle Business Intelligence Standard Edition One on Windows Server 2003 SP2 (DEP OptOut). The exploit requires the login and password to an Oracle account with connect privileges. This exploit must bind to TCP port 80, so it needs root privileges to execute and no other process can be binding to port 80.



Back to exploit index