{"id":"CVE-2006-7217","aliases":[],"url":"https://o3.security/vulnerability/CVE-2006-7217","summary":"Apache Derby SQL Injection","details":"Apache Derby before 10.2.1.6 does not determine schema privilege requirements during the DropSchemaNode bind phase, which allows remote authenticated users to execute arbitrary drop schema statements in SQL authorization mode.","published":"2022-05-01T07:45:41Z","modified":"2024-11-28T05:34:46.520969Z","cvss":null,"epss":{"score":0.01953,"percentile":0.787,"asOf":"2026-08-21"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.derby:derby","fixedVersion":"10.2.1.6"}],"fix":{"url":"https://github.com/apache/derby/commit/28c633d82a776c90fd1cd835a0b66d1c8916d31a","label":"apache/derby@28c633d"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2006-7217"},{"type":"WEB","url":"https://github.com/apache/derby/commit/28c633d82a776c90fd1cd835a0b66d1c8916d31a"},{"type":"PACKAGE","url":"https://github.com/apache/derby"},{"type":"WEB","url":"https://svn.apache.org/viewvc?view=revision&revision=449869"},{"type":"WEB","url":"https://web.archive.org/web/20090406213028/http://www.novell.com/linux/security/advisories/suse_security_summary_report.html"},{"type":"WEB","url":"https://web.archive.org/web/20200301122517/https://issues.apache.org/jira/browse/DERBY-1858"},{"type":"WEB","url":"http://db.apache.org/derby/releases/release-10.2.1.6.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-28T05:34:46.520969Z"}}