SQL injection vulnerability in Oracle Forms 10g allows remote attackers to execute arbitrary SQL commands via the Query/Where feature.Referenceshttp://www.securiteam.com/securitynews/5HP0I0UFFI.htmlhttp://www.red-database-security.com/wp/sql_injection_forms_us.pdfhttps://exchange.xforce.ibmcloud.com/vulnerabilities/20080