Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE
ID 89)(1 flaw)

Hi, the dynamic scan on my application raised a SQL Injection vulnerability pointing to the attached file builder_all.min.js.

 

My application is running on Oracle APEX and this file makes the APEX page designer work with Microsoft Explorer, this is, if I delete the file is not possible work with APEX in Explorer or Edge.

APEX is runing on Apache Tomcat.

Any idea where can be the part of the code that is causing the problem?

And in that case, how can it be solved?

 

Thanks!


Topics (3)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.