The list of values (LOV) in Oracle wwv_flow_utilities.gen_popup_list contains a SQL injection vulnerability. Depending of the APEX application it is possible to inject custom SQL statements.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/51380/Oracle-WWV_FLOW_UTILITIES.txt
Source: https://packetstormsecurity.com/files/51380/Oracle-WWV_FLOW_UTILITIES.txt.html

