« Volver al listado

CVE-2005-2291

Estado: ModificadaMedia (4.6)—

Oracle JDeveloper 9.0.4, 9.0.5, and 10.1.2 passes the cleartext password as a parameter when starting sqlplus, which allows local users to gain sensitive information.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2005-2291",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.6,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": true,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2005-07-18T04:00:00.000",
  "references": [
    {
      "url": "http://marc.info/?l=bugtraq&m=112129082323341&w=2",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.red-database-security.com/advisory/oracle_jdeveloper_passes_plaintext_password.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=112129082323341&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.red-database-security.com/advisory/oracle_jdeveloper_passes_plaintext_password.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Oracle JDeveloper 9.0.4, 9.0.5, and 10.1.2 passes the cleartext password as a parameter when starting sqlplus, which allows local users to gain sensitive information."
    },
    {
      "lang": "es",
      "value": "Oracle JDeveloper 9.0.4, 9.0.5, y 10.1.2 pasa el password en texto plano como parámetro cuando arranca \"sqlplus\", lo que permite que usuarios locales obtengan información confidencial."
    }
  ],
  "lastModified": "2026-06-16T22:14:37.473",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:oracle:jdeveloper:9.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E292E294-90C2-4780-82B6-1265F8FF6040"
            },
            {
              "criteria": "cpe:2.3:a:oracle:jdeveloper:9.0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A5EA5B15-5ABD-459D-8327-9DDC1040C04D"
            },
            {
              "criteria": "cpe:2.3:a:oracle:jdeveloper:10.1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A4C7F9B0-2BF0-430D-ACB3-8E3A41AD31A3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}