« Volver al listado

CVE-2010-2232

Estado: ModificadaAlta (7.5)—

In Apache Derby 10.1.2.1, 10.2.2.0, 10.3.1.4, and 10.4.1.3, Export processing may allow an attacker to overwrite an existing file.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2010-2232",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@apache.org",
      "affectedData": [
        {
          "vendor": "Apache Software Foundation",
          "product": "Apache Derby",
          "versions": [
            {
              "status": "affected",
              "version": "10.1.2.1, 10.2.2.0, 10.3.1.4, 10.4.1.3"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-10-23T13:29:00.233",
  "references": [
    {
      "url": "http://db.apache.org/derby/releases/release-10.6.2.1.html#Note+for+DERBY-2925",
      "tags": [
        "Issue Tracking",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/101562",
      "source": "security@apache.org"
    },
    {
      "url": "https://issues.apache.org/jira/browse/DERBY-2925",
      "tags": [
        "Patch",
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "http://db.apache.org/derby/releases/release-10.6.2.1.html#Note+for+DERBY-2925",
      "tags": [
        "Issue Tracking",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/101562",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://issues.apache.org/jira/browse/DERBY-2925",
      "tags": [
        "Patch",
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In Apache Derby 10.1.2.1, 10.2.2.0, 10.3.1.4, and 10.4.1.3, Export processing may allow an attacker to overwrite an existing file."
    },
    {
      "lang": "es",
      "value": "En Apache Derby 10.1.2.1, 10.2.2.0, 10.3.1.4 y 10.4.1.3, el procesamiento de Export puede permitir que un atacante sobrescriba un archivo existente."
    }
  ],
  "lastModified": "2026-06-16T23:20:21.110",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:derby:10.1.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BF090933-1AC8-4B23-94AE-C9AD0F6372B2"
            },
            {
              "criteria": "cpe:2.3:a:apache:derby:10.2.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "87FD448A-3CDB-4B4E-8E69-5AAD8E5C1835"
            },
            {
              "criteria": "cpe:2.3:a:apache:derby:10.3.1.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DBA7854C-082B-44D0-ABFD-B3E35D0678A0"
            },
            {
              "criteria": "cpe:2.3:a:apache:derby:10.4.1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A526BD06-DB2B-4B91-8DBD-10CCF21695D5"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@apache.org"
}