First published: Mon Oct 03 2016(Updated: )
Apache Derby could allow a remote attacker to obtain sensitive information, caused by a XML external entity (XXE) error when processing XML data by the XML datatype and XmlVTI. An attacker could exploit this vulnerability to read arbitrary files on the system or cause a denial of service.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Derby | =10.1.1.0 | |
Apache Derby | =10.1.2.1 | |
Apache Derby | =10.1.3.1 | |
Apache Derby | =10.2.1.6 | |
Apache Derby | =10.2.2.0 | |
Apache Derby | =10.3.3.0 | |
Apache Derby | =10.4.1.3 | |
Apache Derby | =10.4.2.0 | |
Apache Derby | =10.5.1.1 | |
Apache Derby | =10.5.3.0 | |
Apache Derby | =10.6.1.0 | |
Apache Derby | =10.6.2.1 | |
Apache Derby | =10.7.1.1 | |
Apache Derby | =10.8.1.2 | |
Apache Derby | =10.8.2.2 | |
Apache Derby | =10.8.3.0 | |
Apache Derby | =10.9.1.0 | |
Apache Derby | =10.10.1.1 | |
Apache Derby | =10.10.2.0 | |
Apache Derby | =10.11.1.1 | |
IBM Rational DOORS Next Generation | <=6.0.2 | |
IBM Rational DOORS Next Generation | <=7.0 | |
IBM Rational DOORS Next Generation | <=7.0.1 | |
IBM Rational DOORS Next Generation | <=7.0.2 | |
IBM Rational DOORS Next Generation | <=6.0.6.1 | |
IBM Rational DOORS Next Generation | <=6.0.6 | |
IBM Pub | <=7.0.1 | |
IBM Pub | <=7.0.2 | |
IBM Pub | <=7.0 | |
IBM Engineering Workflow Management (EWM) | <=7.0.2 | |
IBM Engineering Workflow Management (EWM) | <=7.0.1 | |
IBM Rational Team Concert | <=6.0.2 | |
IBM Rational Team Concert | <=6.0.6.1 | |
IBM Engineering Workflow Management (EWM) | <=7.0 | |
IBM Rational Team Concert | <=6.0.6 | |
IBM Global Configuration Management | <=All | |
IBM Engineering Test Management (ETM) | <=7.0.2 | |
IBM Rational Quality Manager (RQM) | <=6.0.6.1 | |
IBM Engineering Test Management (ETM) | <=7.0.1 | |
IBM Rational Quality Manager (RQM) | <=6.0.6 | |
IBM Engineering Test Management (ETM) | <=7.0.0 | |
IBM Rational Quality Manager (RQM) | <=6.0.2 | |
IBM Engineering Requirements Quality Assistant | <=All |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1832 is a vulnerability in Apache Derby that allows a remote attacker to obtain sensitive information or cause a denial of service.
The severity of CVE-2015-1832 is critical with a CVSS score of 9.1.
CVE-2015-1832 affects Apache Derby versions before 10.12.1.1.
A remote attacker can exploit CVE-2015-1832 by leveraging XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby.
Yes, the fix for CVE-2015-1832 is available in Apache Derby version 10.12.1.1 and later.