org.apache.derby:derby@10.12.1.1 vulnerabilities
Contains the core Apache Derby database engine, which also includes the embedded JDBC driver.
-
latest version
10.16.1.1
-
latest non vulnerable version
-
first published
17 years ago
-
latest version published
8 months ago
-
licenses detected
- [0,)
-
package manager
Direct Vulnerabilities
Known vulnerabilities in the org.apache.derby:derby package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
org.apache.derby:derby is a subproject of the Apache DB project. Affected versions of this package are vulnerable to Security Bypass. A specially-crafted network packet can be used to request the Derby Network Server to boot a database whose location and contents are under the user's control. How to fix Security Bypass? Upgrade |
[10.3.1.4,10.14.2.0)
|