CVE-2005-2291

medium

Description

Oracle JDeveloper 9.0.4, 9.0.5, and 10.1.2 passes the cleartext password as a parameter when starting sqlplus, which allows local users to gain sensitive information.

References

http://www.red-database-security.com/advisory/oracle_jdeveloper_passes_plaintext_password.html

http://marc.info/?l=bugtraq&m=112129082323341&w=2

Details

Source: Mitre, NVD

Published: 2005-07-18

Updated: 2016-10-18

Risk Information

CVSS v2

Base Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Severity: Medium