JDeveloper CVE-2005-2292 Information Disclosure Vulnerability

JDeveloper is prone to a information disclosure vulnerability. Oracle JDeveloper 9.0.4, 9.0.5, and 10.1.2 stores cleartext passwords in (1) IDEConnections.xml, (2) XSQLConfig.xml and (3) settings.xml, which allows local users to obtain sensitive information.


 

Privacy Statement
Copyright 2010, SecurityFocus