CVE Vulnerabilities

CVE-2014-0841

Inadequate Encryption Strength

Published: Apr 27, 2018 | Modified: Jun 07, 2018
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

IBM Rational Focal Point 6.4.0, 6.4.1, 6.5.1, 6.5.2, and 6.6.0 use a weak algorithm to hash passwords, which makes it easier for context-dependent attackers to obtain cleartext values via a brute-force attack. IBM X-Force ID: 90704.

Weakness

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

Affected Software

Name Vendor Start Version End Version
Rational_focal_point Ibm 6.4 (including) 6.4 (including)
Rational_focal_point Ibm 6.4.1 (including) 6.4.1 (including)
Rational_focal_point Ibm 6.5.1 (including) 6.5.1 (including)
Rational_focal_point Ibm 6.5.2 (including) 6.5.2 (including)
Rational_focal_point Ibm 6.6 (including) 6.6 (including)

Potential Mitigations

References