CVE Vulnerabilities

CVE-2005-2292

Published: Jul 18, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Oracle JDeveloper 9.0.4, 9.0.5, and 10.1.2 stores cleartext passwords in (1) IDEConnections.xml, (2) XSQLConfig.xml and (3) settings.xml, which allows local users to obtain sensitive information.

Affected Software

NameVendorStart VersionEnd Version
JdeveloperOracle9.0.4 (including)9.0.4 (including)
JdeveloperOracle9.0.5 (including)9.0.5 (including)
JdeveloperOracle10.1.2 (including)10.1.2 (including)

References