3.5
CVE-2006-2539
- EPSS 0.3%
- Veröffentlicht 22.05.2006 23:10:00
- Zuletzt bearbeitet 16.06.2026 22:25:17
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Sybase EAServer 5.0 for HP-UX Itanium, 5.2 for IBM AIX, HP-UX PA-RISC, Linux x86, and Sun Solaris SPARC, and 5.3 for Sun Solaris SPARC does not properly protect passwords when they are being entered via the GUI, which allows local users to obtain the cleartext passwords via the getSelectedText function in javax.swing.JPasswordField component.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.3% | 0.216 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 3.5 | 1.5 | 6.4 |
AV:L/AC:H/Au:S/C:P/I:P/A:P
|
http://secunia.com/advisories/20145
http://www.securityfocus.com/bid/18036
http://www.sybase.com/detail?id=1040665
http://www.vupen.com/english/advisories/2006/1869
https://exchange.xforce.ibmcloud.com/vulnerabilities/26567