Cryptographic issues in Apache Derby - CVE-2009-4269

 

Cryptographic issues in Apache Derby - CVE-2009-4269

Published: June 12, 2023


Vulnerability identifier: #VU77169
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2009-4269
CWE-ID: CWE-310
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to gain access to potentially sensitive information.

The vulnerability exists due to password hash generation algorithm in the BUILTIN authentication functionality for Apache Derby performs a transformation that reduces the size of the set of inputs to SHA-1. A local attacker can gain unauthorized access to sensitive information on the system.


Affected software

Apache Derby
IBM Integration Bus
IBM App Connect Enterprise
IBM Tivoli Network Manager (ITNM)

How to mitigate CVE-2009-4269

Install updates from vendor's website.

Apache Derby - update to 10.6.1.0
IBM Tivoli Network Manager (ITNM) - update to 4.2.0.16

External References

Related Security Bulletins