CVE Vulnerabilities

CVE-2006-0584

Published: Feb 08, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The PSCipher function in PeopleSoft People Tools 8.4x uses PKCS #5 with a fixed DES key to store user passwords, which makes it easier for local users to guess passwords using a dictionary attack that compares output strings.

Affected Software

NameVendorStart VersionEnd Version
PeopletoolsPeoplesoft8.4 (including)8.4 (including)
PeopletoolsPeoplesoft8.40 (including)8.40 (including)
PeopletoolsPeoplesoft8.41 (including)8.41 (including)
PeopletoolsPeoplesoft8.42 (including)8.42 (including)
PeopletoolsPeoplesoft8.43 (including)8.43 (including)
PeopletoolsPeoplesoft8.45.5 (including)8.45.5 (including)
PeopletoolsPeoplesoft8.46.3 (including)8.46.3 (including)

References