Vulnerability Details CVE-2005-2291
Oracle JDeveloper 9.0.4, 9.0.5, and 10.1.2 passes the cleartext password as a parameter when starting sqlplus, which allows local users to gain sensitive information.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 72.8%
CVSS Severity
CVSS v2 Score 4.6
Products affected by CVE-2005-2291
-
cpe:2.3:a:oracle:jdeveloper:10.1.2
-
cpe:2.3:a:oracle:jdeveloper:9.0.4
-
cpe:2.3:a:oracle:jdeveloper:9.0.5