PT-2010-1340 · Apache · Apache Derby

Marcell Major

·

Published

2010-08-16

·

Updated

2022-05-02

·

CVE-2009-4269

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Derby versions prior to 10.6.1.0
Description The issue concerns the password hash generation algorithm in the BUILTIN authentication functionality. It performs a transformation that reduces the size of the set of inputs to SHA-1, resulting in a small search space. This makes it easier for local and possibly remote attackers to crack passwords by generating hash collisions, related to password substitution.
Recommendations For versions prior to 10.6.1.0, update to version 10.6.1.0 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-4269
GHSA-FH32-35W2-RXCC

Affected Products

Apache Derby