« Volver al listado

CVE-2006-0584

Estado: ModificadaBaja (2.1)—

The PSCipher function in PeopleSoft People Tools 8.4x uses PKCS #5 with a fixed DES key to store user passwords, which makes it easier for local users to guess passwords using a dictionary attack that compares output strings.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2006-0584",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2006-02-08T01:02:00.000",
  "references": [
    {
      "url": "http://www.osvdb.org/22952",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/424086/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/16507",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/22952",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/424086/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/16507",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The PSCipher function in PeopleSoft People Tools 8.4x uses PKCS #5 with a fixed DES key to store user passwords, which makes it easier for local users to guess passwords using a dictionary attack that compares output strings."
    },
    {
      "lang": "es",
      "value": "La función PSCipher en PeopleSoft People Tools 8.4x usa PKCS #5 con una clave DES fija para almacenar contraseñas de usuarios, lo que hace fácil para un usuario local adivinar contraseñas con un ataque de diccionario."
    }
  ],
  "lastModified": "2026-06-16T22:20:53.390",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:peoplesoft:peopletools:8.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "70B618A8-48AF-4193-BCD8-7B0F24923860"
            },
            {
              "criteria": "cpe:2.3:a:peoplesoft:peopletools:8.40:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "805FBA0A-0B52-4E61-A45C-E2C9AD48E555"
            },
            {
              "criteria": "cpe:2.3:a:peoplesoft:peopletools:8.41:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F94A7F77-D984-49BD-B59E-EBBC91C56C66"
            },
            {
              "criteria": "cpe:2.3:a:peoplesoft:peopletools:8.42:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FD78CC13-C007-4AB1-912E-16B37D1D55CD"
            },
            {
              "criteria": "cpe:2.3:a:peoplesoft:peopletools:8.43:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ECCB21D3-4FCB-4F0E-8430-B587512D04ED"
            },
            {
              "criteria": "cpe:2.3:a:peoplesoft:peopletools:8.45.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "396A4024-2F8F-4921-8D88-06CBDF21FA42"
            },
            {
              "criteria": "cpe:2.3:a:peoplesoft:peopletools:8.46.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D589760B-C617-403D-8C18-19E9F9FCFBCF"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}