CVE Vulnerabilities

CVE-2005-2292

Published: Jul 18, 2005 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Oracle JDeveloper 9.0.4, 9.0.5, and 10.1.2 stores cleartext passwords in (1) IDEConnections.xml, (2) XSQLConfig.xml and (3) settings.xml, which allows local users to obtain sensitive information.

Affected Software

Name Vendor Start Version End Version
Jdeveloper Oracle 9.0.4 (including) 9.0.4 (including)
Jdeveloper Oracle 9.0.5 (including) 9.0.5 (including)
Jdeveloper Oracle 10.1.2 (including) 10.1.2 (including)

References