Oracle JDeveloper 9.0.4, 9.0.5, and 10.1.2 passes the cleartext password as a parameter when starting sqlplus, which allows local users to gain sensitive information.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jdeveloper | Oracle | 9.0.4 (including) | 9.0.4 (including) |
Jdeveloper | Oracle | 9.0.5 (including) | 9.0.5 (including) |
Jdeveloper | Oracle | 10.1.2 (including) | 10.1.2 (including) |