← Back

CVE-2006-7217

nvd nist
Published: Jul 5, 2007Modified: Apr 23, 2026

JSON object

Loading...
4.0
Vector
AV:N/AC:L/Au:S/C:N/I:P/A:N
Exploitability: 8.0 / Impact: 2.9
Source: NVD

Description

Apache Derby before 10.2.1.6 does not determine schema privilege requirements during the DropSchemaNode bind phase, which allows remote authenticated users to execute arbitrary drop schema statements in SQL authorization mode.

Affected (3)

Products: Apache: Derby
1 product
Derby
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Version 10.1.1.0
Version 10.1.2.1
Version 10.1.3.1

Timeline

No history available yet.