Apache Software Foundation Derby

CPE Details

Apache Software Foundation Derby
-
2007-08-23
19h05 +00:00
2008-03-25
17h12 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:apache:derby:-:*:*:*:*:*:*:*

Informations

Vendor

apache

Product

derby

Version

-

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2009-4269 2010-08-16 17h00 +00:00 The password hash generation algorithm in the BUILTIN authentication functionality for Apache Derby before 10.6.1.0 performs a transformation that reduces the size of the set of inputs to SHA-1, which produces a small search space that makes it easier for local and possibly remote attackers to crack passwords by generating hash collisions, related to password substitution.
2.1
CVE-2005-4849 2007-07-05 20h00 +00:00 Apache Derby before 10.1.2.1 exposes the (1) user and (2) password attributes in cleartext via (a) the RDBNAM parameter of the ACCSEC command and (b) the output of the DatabaseMetaData.getURL function, which allows context-dependent attackers to obtain sensitive information.
5