Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS12N2NxLXBxN3YtbWg1ds2Vag

Apache Derby SQL Injection

Apache Derby before 10.2.1.6 does not determine schema privilege requirements during the DropSchemaNode bind phase, which allows remote authenticated users to execute arbitrary drop schema statements in SQL authorization mode.

Permalink: https://github.com/advisories/GHSA-v7cq-pq7v-mh5v
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12N2NxLXBxN3YtbWg1ds2Vag
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: almost 2 years ago
Updated: 3 months ago


Identifiers: GHSA-v7cq-pq7v-mh5v, CVE-2006-7217
References: Repository: https://github.com/apache/derby
Blast Radius: 0.0

Affected Packages

maven:org.apache.derby:derby
Dependent packages: 2,009
Dependent repositories: 22,059
Downloads:
Affected Version Ranges: < 10.2.1.6
Fixed in: 10.2.1.6
All affected versions:
All unaffected versions: