CVE-2005-2292 Information
Feb 14, 2021
cve
Description
Oracle JDeveloper 9.0.4 9.0.5 and 10.1.2 stores cleartext passwords in (1) IDEConnections.xml (2) XSQLConfig.xml and (3) settings.xml which allows local users to obtain sensitive information.
Reference
http://marc.info/?l=bugtraq&m=112129177927502&w=2 http://secunia.com/advisories/15991/ http://www.oracle.com/technology/deploy/security/pdf/cpujul2005.html http://www.red-database-security.com/advisory/oracle_jdeveloper_plaintext_password.html https://exchange.xforce.ibmcloud.com/vulnerabilities/21342
Share on: