← Back

CVE-2006-7216

nvd nist
Published: Jul 5, 2007Modified: Apr 23, 2026

JSON object

Loading...
4.0
Vector
AV:N/AC:L/Au:S/C:N/I:N/A:P
Exploitability: 8.0 / Impact: 2.9
Source: NVD

Description

Apache Derby before 10.2.1.6 does not determine privilege requirements for lock table statements at compilation time, and consequently does not enforce privilege requirements at execution time, which allows remote authenticated users to lock arbitrary tables.

Affected (3)

Products: Apache: Derby
1 product
Derby
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Version 10.1.1.0
Version 10.1.2.1
Version 10.1.3.1

References (4)

Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch

Timeline

No history available yet.