Skip to Main Content

SQL Developer

Announcement

For appeals, questions and feedback about Oracle Forums, please email oracle-forums-moderators_us@oracle.com. Technical questions should be asked in the appropriate category. Thank you!

SET CODESCAN - no help content found in Help Center

kenpJan 6 2020 — edited Jan 6 2020

I am interested in learning more about this recently added enhancement documented under

'Oracle SQL Developer 19.4 Release Notes'

- 'Added SET CODESCAN to look for SQL Injection vulnerabilities'

Has anyone found more information on CODESCAN?

thanks,

Ken

Comments

2926792

select object_name,object_type,status,owner from dba_objects where owner='SYS' and status='INVALID';

 

select comp_name, version, status from dba_registry;

As considered,SYS.KUPU$UTILITIES_INT should be invalid.

connect / as sysdba;

 

SQL> set echo on

SQL> SPOOL /tmp/catalog.log

SQL> @catalog.sql <--------------$ORACLE_HOME/rdbms/admin

SQL> SPOOL off

SQL> SPOOL /tmp/catproc.log

SQL> @catproc.sql <--------------$ORACLE_HOME/rdbms/admin

SQL> SPOOL off

SQL> SPOOL /tmp/utlrp.log

SQL> @utlrp.sql <--------------$ORACLE_HOME/rdbms/admin

SQL> SPOOL off

 

Execute utlrp.sql script for multiple times like 5 times in 3 minute interval.

Wesley D-Oracle

The direct approach:

sqlplus / as sysdba
@?/rdbms/admin/prvthpui.plb
@?/rdbms/admin/prvtbpui.plb
alter package KUPW$WORKER compile body;

Confirm if "KUPU$UTILITIES_INT" has successfully validated.

1 - 2

Post Details

Added on Jan 6 2020
3 comments
161 views