Oracle JDeveloper 9
Oracle JDeveloper 9.0.4, 9.0.5, and 10.1.2 passes the cleartext password as a parameter when starting sqlplus, which allows local users to gain sensitive information.
Exploitability
AV:L
AC:L
Au:N
Impact
C:P
I:P
A:P
4.6/AV:L/AC:L/Au:N/C:P/I:P/A:P