PT-2002-2594 · Microsoft · Sql Server

CVE-2002-1872

·

Publicado

2002-12-31

·

Atualizado

2024-02-14

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft SQL Server versions 6.0 through 2000
Description The issue allows remote attackers to sniff and decrypt passwords due to the use of weak password encryption (XOR) when SQL Authentication is enabled.
Recommendations For Microsoft SQL Server versions 6.0 through 2000, consider disabling SQL Authentication or restricting its use to minimize the risk of exploitation until a more secure authentication method can be implemented.

Correção

Inadequate Encryption Strength

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2002-1872

Produtos afetados

Sql Server