Vulnerability Name:

CVE-2006-7217 (CCN-36335)

Assigned:2006-09-15
Published:2006-09-15
Updated:2008-09-05
Summary:Apache Derby before 10.2.1.6 does not determine schema privilege requirements during the DropSchemaNode bind phase, which allows remote authenticated users to execute arbitrary drop schema statements in SQL authorization mode.
CVSS v3 Severity:2.6 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N)
3.0 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
2.1 Low (CCN CVSS v2 Vector: AV:N/AC:H/Au:S/C:N/I:P/A:N)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:S/C:N/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2006-7217

Source: CONFIRM
Type: Patch
http://db.apache.org/derby/releases/release-10.2.1.6.html

Source: CCN
Type: DERBY-1858
A schema can be dropped by a non-schema owner in SQL authorization mode

Source: CONFIRM
Type: UNKNOWN
http://issues.apache.org/jira/browse/DERBY-1858

Source: SECUNIA
Type: UNKNOWN
28636

Source: SUSE
Type: UNKNOWN
SUSE-SR:2008:002

Source: CCN
Type: OSVDB ID: 45740
Apache Derby DropSchemaNode Bind Phase Arbitrary Scheme Statement Dropping

Source: XF
Type: UNKNOWN
derby-schema-privilege-escalation(36335)

Source: SUSE
Type: SUSE-SR:2008:002
SUSE Security Summary Report

Vulnerable Configuration:Configuration 1:
  • cpe:/a:apache:derby:10.1.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:apache:derby:10.1.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:apache:derby:10.1.3.1:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:apache:derby:10.3.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:apache:derby:10.2.2.0:*:*:*:*:*:*:*
  • OR cpe:/a:apache:derby:10.2.1.6:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20067217
    V
    CVE-2006-7217
    2022-06-30
    oval:org.opensuse.security:def:112147
    P
    derby-10.11.1.1-3.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:26225
    P
    Security update for libsndfile (Important)
    2022-01-05
    oval:org.opensuse.security:def:105683
    P
    Security update for xorg-x11-server (Important)
    2021-12-14
    oval:org.opensuse.security:def:26144
    P
    Security update for libqt5-qtsvg (Moderate)
    2021-10-11
    oval:org.opensuse.security:def:36391
    P
    derby-10.3.1.4-1.16 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:26716
    P
    gvim on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26282
    P
    Security update for libproxy (Important)
    2020-12-01
    oval:org.opensuse.security:def:26619
    P
    ntp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26016
    P
    Security update for ImageMagick (Important)
    2020-12-01
    oval:org.opensuse.security:def:27354
    P
    vsftpd-openssl1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26366
    P
    Security update for kdelibs4, kio (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25940
    P
    Security update for mariadb (Important)
    2020-12-01
    oval:org.opensuse.security:def:26658
    P
    MozillaFirefox on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27389
    P
    derby on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26517
    P
    NetworkManager-gnome on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25941
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26672
    P
    avahi on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26570
    P
    kdebase3-runtime on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25952
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    BACK
    apache derby 10.1.1.0
    apache derby 10.1.2.1
    apache derby 10.1.3.1
    apache derby 10.3.1.4
    apache derby 10.2.2.0
    apache derby 10.2.1.6