Cleartext Exposure in Apache Derby by Apache Software Foundation
CVE-2005-4849

Currently unrated

Key Information:

Vendor

Apache

Status
Vendor
CVE Published:
31 December 2005

What is CVE-2005-4849?

Apache Derby prior to version 10.1.2.1 exposes sensitive user credentials in cleartext through specific commands and functions. Attackers can exploit this vulnerability via the RDBNAM parameter of the ACCSEC command and through the DatabaseMetaData.getURL function output, potentially leading to unauthorized access to sensitive data.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.