Oracle JDeveloper 9.0.4, 9.0.5, and 10.1.2 passes the cleartext password as a parameter when starting sqlplus, which allows local users to gain sensitive information.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Jdeveloper | Oracle | 9.0.4 (including) | 9.0.4 (including) |
| Jdeveloper | Oracle | 9.0.5 (including) | 9.0.5 (including) |
| Jdeveloper | Oracle | 10.1.2 (including) | 10.1.2 (including) |