PT-2010-1340 · Apache · Apache Derby

Marcell Major

·

Publicado

2010-08-16

·

Atualizado

2022-05-02

·

CVE-2009-4269

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Derby versions prior to 10.6.1.0
Description The issue concerns the password hash generation algorithm in the BUILTIN authentication functionality. It performs a transformation that reduces the size of the set of inputs to SHA-1, resulting in a small search space. This makes it easier for local and possibly remote attackers to crack passwords by generating hash collisions, related to password substitution.
Recommendations For versions prior to 10.6.1.0, update to version 10.6.1.0 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-4269
GHSA-FH32-35W2-RXCC

Produtos afetados

Apache Derby