The password hash generation algorithm in the BUILTIN authentication functionality...
Vulnerability Description
The password hash generation algorithm in the BUILTIN authentication functionality for Apache Derby before 10.6.1.0 performs a transformation that reduces the size of the set of inputs to SHA-1, which produces a small search space that makes it easier for local and possibly remote attackers to crack passwords by generating hash collisions, related to password substitution.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-4269
Credits & Attribution
No credits recorded in the NVD database.
References
- http://marc.info/?l=apache-db-general&m=127428514905504&w=1
- http://secunia.com/advisories/42948
- https://issues.apache.org/jira/browse/DERBY-4483
- http://blogs.sun.com/kah/entry/derby_10_6_1_has
- http://www.vupen.com/english/advisories/2011/0149
- http://secunia.com/advisories/42970
- http://marcellmajor.com/derbyhash.html
- http://www.securitytracker.com/id?1024977
- http://db.apache.org/derby/releases/release-10.6.1.0.cgi#Fix+for+Security+Bug+CVE-2009-4269
- http://www.securityfocus.com/bid/42637
- http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html
More from apache
View All →Affected Vendor
apache
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.