CVE-2006-7217
Estado: ModificadaMedia (4)—
Apache Derby before 10.2.1.6 does not determine schema privilege requirements during the DropSchemaNode bind phase, which allows remote authenticated users to execute arbitrary drop schema statements in SQL authorization mode.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N
- Puntuación base: 4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.95%
- Percentil entre todas las CVEs puntuadas: 80
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://db.apache.org/derby/releases/release-10.2.1.6.html
- http://issues.apache.org/jira/browse/DERBY-1858
- http://secunia.com/advisories/28636
- http://www.novell.com/linux/security/advisories/suse_security_summary_report.html
- http://db.apache.org/derby/releases/release-10.2.1.6.html
- http://issues.apache.org/jira/browse/DERBY-1858
- http://secunia.com/advisories/28636
- http://www.novell.com/linux/security/advisories/suse_security_summary_report.html
JSON original (NVD)
Mostrar
{
"id": "CVE-2006-7217",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:N",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-07-05T20:30:00.000",
"references": [
{
"url": "http://db.apache.org/derby/releases/release-10.2.1.6.html",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://issues.apache.org/jira/browse/DERBY-1858",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/28636",
"source": "cve@mitre.org"
},
{
"url": "http://www.novell.com/linux/security/advisories/suse_security_summary_report.html",
"source": "cve@mitre.org"
},
{
"url": "http://db.apache.org/derby/releases/release-10.2.1.6.html",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://issues.apache.org/jira/browse/DERBY-1858",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/28636",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.novell.com/linux/security/advisories/suse_security_summary_report.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Apache Derby before 10.2.1.6 does not determine schema privilege requirements during the DropSchemaNode bind phase, which allows remote authenticated users to execute arbitrary drop schema statements in SQL authorization mode."
},
{
"lang": "es",
"value": "Apache Derby anterior a 10.2.1.6 no determina los requerimientos de privilegios de esquema durante la fase DropSchemaNode, lo cual permite a usuarios autenticados remotos ejecutar instrucciones de borrado de esquema en modo de autorización SQL."
}
],
"lastModified": "2026-06-16T22:34:35.920",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:derby:10.1.1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "909C93D8-EE69-4614-90A4-29289DA6D700"
},
{
"criteria": "cpe:2.3:a:apache:derby:10.1.2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BF090933-1AC8-4B23-94AE-C9AD0F6372B2"
},
{
"criteria": "cpe:2.3:a:apache:derby:10.1.3.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C06539EB-A87C-47C2-8E13-88D9B1CAD7D8"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}