The password hash generation algorithm in the BUILTIN authentication functionality for Apache Derby before 10.6.1.0 performs a transformation that reduces the size of the set of inputs to SHA-1, which produces a small search space that makes it easier for local and possibly remote attackers to crack passwords by generating hash collisions, related to password substitution.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2010-08-16T19:00:00
Updated: 2024-08-07T06:54:10.308Z
Reserved: 2009-12-10T00:00:00
Link: CVE-2009-4269
Vulnrichment
No data.
NVD
Status : Modified
Published: 2010-08-16T20:00:01.183
Modified: 2024-11-21T01:09:16.980
Link: CVE-2009-4269
Redhat
No data.