PT-2002-2594 · Microsoft · Sql Server

Published

2002-12-31

·

Updated

2024-02-14

·

CVE-2002-1872

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft SQL Server versions 6.0 through 2000
Description The issue allows remote attackers to sniff and decrypt passwords due to the use of weak password encryption (XOR) when SQL Authentication is enabled.
Recommendations For Microsoft SQL Server versions 6.0 through 2000, consider disabling SQL Authentication or restricting its use to minimize the risk of exploitation until a more secure authentication method can be implemented.

Fix

Inadequate Encryption Strength

Weakness Enumeration

Related Identifiers

CVE-2002-1872

Affected Products

Sql Server