Known vulnerabilities in Apache Derby

Software: Apache Derby
Software CPE: cpe:2.3:a:apache_foundation:apache_derby:*:*:*:*:*:*:*:*
Total vulnerabilities: 3
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Apache Derby Apache Derby is affected by 3 known vulnerabilities: 1 high, 2 low Critical High Medium Low

Vulnerabilities (3)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU83545 - Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CVE-2022-46337
CWE-90 High
No
No
10.17.1.0 28.11.2023 SB2023112861
SB2024011806
SB2024020107
and 34 more
#VU12420 - Permissions, Privileges, and Access Controls
CVE-2018-1313
CWE-264 Low
No
No
- 08.05.2018 SB2018050809
SB2022110302
SB2023040530
and 8 more
#VU735 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2015-1832
CWE-611 Low
No
No
- 04.10.2016 SB2015071704
SB2020042337
SB2020102845
and 6 more