CVE Vulnerabilities

CVE-2005-2291

Published: Jul 18, 2005 | Modified: Oct 18, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Oracle JDeveloper 9.0.4, 9.0.5, and 10.1.2 passes the cleartext password as a parameter when starting sqlplus, which allows local users to gain sensitive information.

Affected Software

Name Vendor Start Version End Version
Jdeveloper Oracle 9.0.4 (including) 9.0.4 (including)
Jdeveloper Oracle 9.0.5 (including) 9.0.5 (including)
Jdeveloper Oracle 10.1.2 (including) 10.1.2 (including)

References