CVE Vulnerabilities

CVE-2006-0584

Published: Feb 08, 2006 | Modified: Oct 19, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The PSCipher function in PeopleSoft People Tools 8.4x uses PKCS #5 with a fixed DES key to store user passwords, which makes it easier for local users to guess passwords using a dictionary attack that compares output strings.

Affected Software

Name Vendor Start Version End Version
Peopletools Peoplesoft 8.4 (including) 8.4 (including)
Peopletools Peoplesoft 8.40 (including) 8.40 (including)
Peopletools Peoplesoft 8.41 (including) 8.41 (including)
Peopletools Peoplesoft 8.42 (including) 8.42 (including)
Peopletools Peoplesoft 8.43 (including) 8.43 (including)
Peopletools Peoplesoft 8.45.5 (including) 8.45.5 (including)
Peopletools Peoplesoft 8.46.3 (including) 8.46.3 (including)

References