SQL Developer (MOSC)

MOSC Banner

Is there a CVE threat assessment rating for the save password feature?

in SQL Developer (MOSC) 1 commentAnswered ✓

There is open source information suggesting that passwords saved in SQL Developer can be easily decrypted. See SQL Developer Password Decryptor (abskmj.github.io) and maaaaz/sqldeveloperpassworddecryptor: A simple script to decrypt stored passwords from the Oracle SQL Developer IDE (github.com).

I would like to know if a threat assessment has been carried for SQL Developer v23 in the light of this material to help understand whether we can exploit this feature securely. If a threat assessment hasn't been carried out then any suggestions on taking this forward would be appreciated.

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center