Apache Derby before 10.1.2.1 exposes the (1) user and (2) password attributes in cleartext via (a) the RDBNAM parameter of the ACCSEC command and (b) the output of the DatabaseMetaData.getURL function, which allows context-dependent attackers to obtain sensitive information.
References
Configurations
Information
Published : 2005-12-30 21:00
Updated : 2008-09-04 21:00
NVD link : CVE-2005-4849
Mitre link : CVE-2005-4849
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
apache
- derby