CVE Vulnerabilities

CVE-2006-0584

Published: Feb 08, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The PSCipher function in PeopleSoft People Tools 8.4x uses PKCS #5 with a fixed DES key to store user passwords, which makes it easier for local users to guess passwords using a dictionary attack that compares output strings.

Affected Software

Name Vendor Start Version End Version
Peopletools Peoplesoft 8.4 (including) 8.4 (including)
Peopletools Peoplesoft 8.40 (including) 8.40 (including)
Peopletools Peoplesoft 8.41 (including) 8.41 (including)
Peopletools Peoplesoft 8.42 (including) 8.42 (including)
Peopletools Peoplesoft 8.43 (including) 8.43 (including)
Peopletools Peoplesoft 8.45.5 (including) 8.45.5 (including)
Peopletools Peoplesoft 8.46.3 (including) 8.46.3 (including)

References