CVE-2005-2291: Medium severity Oracle JDeveloper vulnerability
Oracle JDeveloper 9.0.4, 9.0.5, and 10.1.2 passes the cleartext password as a parameter when starting sqlplus, which allows local users to gain sensitive information.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2005-2291?
CVE-2005-2291 is classified as a medium severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2005-2291?
To fix CVE-2005-2291, it is recommended to upgrade to a newer, patched version of Oracle JDeveloper that does not expose passwords in cleartext.
Who is affected by CVE-2005-2291?
CVE-2005-2291 affects local users of Oracle JDeveloper versions 9.0.4, 9.0.5, and 10.1.2.
What type of vulnerability is CVE-2005-2291?
CVE-2005-2291 is an information disclosure vulnerability that allows unauthorized access to sensitive data.
Can CVE-2005-2291 be exploited remotely?
CVE-2005-2291 cannot be exploited remotely as it requires local access to the system running the affected version of Oracle JDeveloper.