PT-2006-3486 · Oracle+1 · Javax.Swing.Jpasswordfield+1

Published

2006-05-22

·

Updated

2017-07-20

·

CVE-2006-2539

CVSS v2.0

3.5

Low

VectorAV:L/AC:H/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Sybase EAServer versions 5.0 for HP-UX Itanium, 5.2 for IBM AIX, HP-UX PA-RISC, Linux x86, and Sun Solaris SPARC, and 5.3 for Sun Solaris SPARC
Description The issue concerns the improper protection of passwords when entered via the GUI, allowing local users to obtain cleartext passwords. This is achieved through the getSelectedText function in the javax.swing.JPasswordField component.
Recommendations For Sybase EAServer version 5.0 on HP-UX Itanium, consider restricting access to the GUI until a fix is available. For Sybase EAServer version 5.2 on IBM AIX, HP-UX PA-RISC, Linux x86, and Sun Solaris SPARC, avoid using the getSelectedText function in the javax.swing.JPasswordField component until the issue is resolved. For Sybase EAServer version 5.3 on Sun Solaris SPARC, temporarily disable the GUI password entry feature to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2539

Affected Products

Sybase Easerver
Javax.Swing.Jpasswordfield