Total vulnerabilities in the database
Oracle JDeveloper 9.0.4, 9.0.5, and 10.1.2 stores cleartext passwords in (1) IDEConnections.xml, (2) XSQLConfig.xml and (3) settings.xml, which allows local users to obtain sensitive information.
Software | From | Fixed in |
---|---|---|
oracle / jdeveloper | 9.0.4 | 9.0.4.x |
oracle / jdeveloper | 9.0.5 | 9.0.5.x |
oracle / jdeveloper | 10.1.2 | 10.1.2.x |