Cleartext Exposure in Apache Derby by Apache Software Foundation
CVE-2005-4849
Currently unrated
What is CVE-2005-4849?
Apache Derby prior to version 10.1.2.1 exposes sensitive user credentials in cleartext through specific commands and functions. Attackers can exploit this vulnerability via the RDBNAM parameter of the ACCSEC command and through the DatabaseMetaData.getURL function output, potentially leading to unauthorized access to sensitive data.