Vulnerabilities > CVE-2002-1657 - Use of Password Hash With Insufficient Computational Effort vulnerability in Postgresql 7.3.19

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
postgresql
CWE-916

Summary

PostgreSQL uses the username for a salt when generating passwords, which makes it easier for remote attackers to guess passwords via a brute force attack.

Vulnerable Configurations

Part Description Count
Application
Postgresql
1