2.1
CVSSv2

CVE-2009-4269

Published: 16/08/2010 Updated: 26/01/2011
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The password hash generation algorithm in the BUILTIN authentication functionality for Apache Derby prior to 10.6.1.0 performs a transformation that reduces the size of the set of inputs to SHA-1, which produces a small search space that makes it easier for local and possibly remote malicious users to crack passwords by generating hash collisions, related to password substitution.

Vulnerable Product Search on Vulmon Subscribe to Product

apache derby