CVE-2010-2232
published 2017-10-23CVE-2010-2232: In Apache Derby 10.1.2.1, 10.2.2.0, 10.3.1.4, and 10.4.1.3, Export processing may allow an attacker to overwrite an existing file.
PriorityP341high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
3.80%
88.7th percentile
In Apache Derby 10.1.2.1, 10.2.2.0, 10.3.1.4, and 10.4.1.3, Export processing may allow an attacker to overwrite an existing file.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | derby | — | — |
| apache | derby | — | — |
| apache | derby | — | — |
| apache | derby | — | — |
| apache_software_foundation | apache_derby | — | — |
| debian | derby | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper Access Control in Apache Derby
ghsa·2022-05-17
CVE-2010-2232 [HIGH] CWE-284 Improper Access Control in Apache Derby
Improper Access Control in Apache Derby
In Apache Derby 10.1.2.1, 10.2.2.0, 10.3.1.4, and 10.4.1.3, Export processing may allow an attacker to overwrite an existing file.
OSV
Improper Access Control in Apache Derby
osv·2022-05-17
CVE-2010-2232 [HIGH] Improper Access Control in Apache Derby
Improper Access Control in Apache Derby
In Apache Derby 10.1.2.1, 10.2.2.0, 10.3.1.4, and 10.4.1.3, Export processing may allow an attacker to overwrite an existing file.
Red Hat
derby: SYSCS_EXPORT_TABLE can be used to overwrite derby files
vendor_redhat·2017-10-23·CVSS 7.5
CVE-2010-2232 [HIGH] CWE-212 derby: SYSCS_EXPORT_TABLE can be used to overwrite derby files
derby: SYSCS_EXPORT_TABLE can be used to overwrite derby files
In Apache Derby 10.1.2.1, 10.2.2.0, 10.3.1.4, and 10.4.1.3, Export processing may allow an attacker to overwrite an existing file.
Package: derby (Red Hat BPM Suite 6) - Not affected
Package: derby (Red Hat JBoss BRMS 5) - Not affected
Package: derby (Red Hat JBoss BRMS 6) - Not affected
Package: derby (Red Hat JBoss Fuse 6) - Not affected
Package: derby (Red Hat Single Sign-On 7) - Not affected
Debian
CVE-2010-2232: derby - In Apache Derby 10.1.2.1, 10.2.2.0, 10.3.1.4, and 10.4.1.3, Export processing ma...
vendor_debian·2010·CVSS 7.5
CVE-2010-2232 [HIGH] CVE-2010-2232: derby - In Apache Derby 10.1.2.1, 10.2.2.0, 10.3.1.4, and 10.4.1.3, Export processing ma...
In Apache Derby 10.1.2.1, 10.2.2.0, 10.3.1.4, and 10.4.1.3, Export processing may allow an attacker to overwrite an existing file.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
http://db.apache.org/derby/releases/release-10.6.2.1.html#Note+for+DERBY-2925http://www.securityfocus.com/bid/101562https://issues.apache.org/jira/browse/DERBY-2925http://db.apache.org/derby/releases/release-10.6.2.1.html#Note+for+DERBY-2925http://www.securityfocus.com/bid/101562https://issues.apache.org/jira/browse/DERBY-2925
2017-10-23
Published