4

CVE-2006-7216

Apache Derby before 10.2.1.6 does not determine privilege requirements for lock table statements at compilation time, and consequently does not enforce privilege requirements at execution time, which allows remote authenticated users to lock arbitrary tables.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Derby Version 10.1.1.0
Apache ≫ Derby Version 10.1.2.1
Apache ≫ Derby Version 10.1.3.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.18% 0.8
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:N/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://db.apache.org/derby/releases/release-10.2.1.6.html
Patch
http://issues.apache.org/jira/browse/DERBY-1708
Patch