Known vulnerabilities in Apache Derby
Vendor:
Apache Foundation
Software:
Apache Derby
Software CPE:
cpe:2.3:a:apache_foundation:apache_derby:*:*:*:*:*:*:*:*
Website:
https://www.apache.org
Total vulnerabilities:
3
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
10.17.1.0
10.16.1.1
10.15.2.0
10.15.1.3
10.4.1.3
10.8.3000000.1405108
10.14.2.0
10.14.1.0
10.13.1.1
10.12.1.1
10.14.0.0
10.13.0.0
10.12.0.0
10.11.0.0
10.10.0.0
10.9.0.0
10.8.0.0
10.7.0.0
10.6.0.0
10.5.0.0
10.4.0.0
10.11.1.1
10.10.2.0
10.10.1.1
10.8.3.0
10.9.1.0
10.8.2.2
10.8.1.2
10.7.1.1
10.6.2.1
10.6.1.0
10.5.3.0
10.5.1.1
10.4.2.0
10.3.3.0
10.4.3.1
10.3.2.1
10.3.1.4
10.2.2.0
10.2.1.6
10.1.3.1
10.1.2.1
10.1.1
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU83545 - Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') CVE-2022-46337 |
CWE-90 | High | 10.17.1.0 | 28.11.2023 |
SB2023112861 SB2024011806 SB2024020107 and 34 more |
||
| #VU12420 - Permissions, Privileges, and Access Controls CVE-2018-1313 |
CWE-264 | Low | - | 08.05.2018 |
SB2018050809 SB2022110302 SB2023040530 and 8 more |
||
| #VU735 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2015-1832 |
CWE-611 | Low | - | 04.10.2016 |
SB2015071704 SB2020042337 SB2020102845 and 6 more |