Apache Derby before 10.2.1.6 does not determine privilege requirements for lock table statements at compilation time, and consequently does not enforce privilege requirements at execution time, which allows remote authenticated users to lock arbitrary tables.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2007-07-05T20:00:00Z
Updated: 2024-09-16T23:46:46.570Z
Reserved: 2007-07-05T00:00:00Z
Link: CVE-2006-7216
Vulnrichment
No data.
NVD
Status : Modified
Published: 2007-07-05T20:30:00.000
Modified: 2024-11-21T00:24:39.590
Link: CVE-2006-7216
Redhat
No data.