QID 996005
Date Published: 2023-11-21
QID 996005: Java (Maven) Security Update for org.apache.derby:derby (GHSA-rcjc-c4pj-xxrp)
A cleverly devised username might bypass LDAP authentication checks. In LDAP-authenticated Derby installations, this could let an attacker fill up the disk by creating junk Derby databases. In LDAP-authenticated Derby installations, this could also allow the attacker to execute malware which was visible to and executable by the account which booted the Derby server. In LDAP-protected databases which weren't also protected by SQL GRANT/REVOKE authorization, this vulnerability could also let an attacker view and corrupt sensitive data and run sensitive database functions and procedures.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-rcjc-c4pj-xxrp for updates and patch information.
Vendor References
- GHSA-rcjc-c4pj-xxrp -
github.com/advisories/GHSA-rcjc-c4pj-xxrp
CVEs related to QID 996005
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-rcjc-c4pj-xxrp | org.apache.derby:derby |
|