« Volver al listado

CVE-2006-7217

Estado: ModificadaMedia (4)—

Apache Derby before 10.2.1.6 does not determine schema privilege requirements during the DropSchemaNode bind phase, which allows remote authenticated users to execute arbitrary drop schema statements in SQL authorization mode.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2006-7217",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-07-05T20:30:00.000",
  "references": [
    {
      "url": "http://db.apache.org/derby/releases/release-10.2.1.6.html",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://issues.apache.org/jira/browse/DERBY-1858",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/28636",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.novell.com/linux/security/advisories/suse_security_summary_report.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://db.apache.org/derby/releases/release-10.2.1.6.html",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://issues.apache.org/jira/browse/DERBY-1858",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/28636",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.novell.com/linux/security/advisories/suse_security_summary_report.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Apache Derby before 10.2.1.6 does not determine schema privilege requirements during the DropSchemaNode bind phase, which allows remote authenticated users to execute arbitrary drop schema statements in SQL authorization mode."
    },
    {
      "lang": "es",
      "value": "Apache Derby anterior a 10.2.1.6 no determina los requerimientos de privilegios de esquema durante la fase DropSchemaNode, lo cual permite a usuarios autenticados remotos ejecutar instrucciones de borrado de esquema en modo de autorización SQL."
    }
  ],
  "lastModified": "2026-06-16T22:34:35.920",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:derby:10.1.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "909C93D8-EE69-4614-90A4-29289DA6D700"
            },
            {
              "criteria": "cpe:2.3:a:apache:derby:10.1.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BF090933-1AC8-4B23-94AE-C9AD0F6372B2"
            },
            {
              "criteria": "cpe:2.3:a:apache:derby:10.1.3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C06539EB-A87C-47C2-8E13-88D9B1CAD7D8"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}