Imperva Cyber Community

communities_1.jpg
 View Only
  • 1.  SQL injection report for Database users and application users

    Posted 09-24-2025 03:26

    I have a SQL Injection report in place for oracle and SQL database, but i want separate report for application users and normal database users (people accessing database via application and people accessing database directly)

    now i am adding application user and database username in two different policies and excluding one single user so that all other users take hit on these policies.

    Please confirm if this approach is correct or how can i achieve this, please note with existing report i am able to get result but with new one i am not

     


    #DatabaseActivityMonitoring

    ------------------------------
    Mohammad Musaib Rather
    Support User
    StarLink DMCC
    Dubai
    ------------------------------


  • 2.  RE: SQL injection report for Database users and application users

    Posted 28 days ago

    Hi Muhammad,

    THanks for posting. I notice that there has been no response to this query. 

    Were you able to find the information you needed? 

    Thanks,



    ------------------------------
    Sarah Lamont
    Digital Community Manager
    ------------------------------



  • 3.  RE: SQL injection report for Database users and application users

    Posted 25 days ago

    Hi Sarah,

    Thank you for your response, I was able to find it. 



    ------------------------------
    Mohammad Musaib Rather

    Dubai
    ------------------------------



  • 4.  RE: SQL injection report for Database users and application users

    Posted 24 days ago

    Super! I am glad to hear that you found it.

    If there was a particular link that was helpful, would you mind sharing it here so that other members can benefit? 

    Thank you!



    ------------------------------
    Sarah Lamont
    Digital Community Manager
    ------------------------------



  • 5.  RE: SQL injection report for Database users and application users

    Posted 23 days ago

    i dont have any particular online kb to share, however i found this we can achieve by using data enrichment from available match criteria and define the username field there.



    ------------------------------
    Mohammad Musaib Rather

    Dubai
    ------------------------------