First published: Wed Feb 08 2006(Updated: )
The PSCipher function in PeopleSoft People Tools 8.4x uses PKCS #5 with a fixed DES key to store user passwords, which makes it easier for local users to guess passwords using a dictionary attack that compares output strings.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle PeopleSoft PeopleTools | =8.42 | |
Oracle PeopleSoft PeopleTools | =8.43 | |
Oracle PeopleSoft PeopleTools | =8.41 | |
Oracle PeopleSoft PeopleTools | =8.46.3 | |
Oracle PeopleSoft PeopleTools | =8.4 | |
Oracle PeopleSoft PeopleTools | =8.45.5 | |
Oracle PeopleSoft PeopleTools | =8.40 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0584 is considered to have a medium severity due to its potential for dictionary attacks on user passwords.
To mitigate CVE-2006-0584, it is recommended to upgrade to a newer version of Oracle PeopleSoft PeopleTools that does not use fixed DES keys.
CVE-2006-0584 affects versions 8.40 through 8.46.3 of Oracle PeopleSoft PeopleTools.
CVE-2006-0584 can lead to unauthorized access as local users can guess passwords more easily through dictionary attacks.
Yes, CVE-2006-0584 remains a concern for organizations using the affected versions of PeopleSoft PeopleTools without proper remediation.