Make SYSCS_UTIL.SYSCS_GET_DATABASE_PROPERTY('derby.user.<username>') return
NULL instead of the hash value of the password
---------------------------------------------------------------------------------------------------------------------------
Key: DERBY-3014
URL: https://issues.apache.org/jira/browse/DERBY-3014
Project: Derby
Issue Type: Improvement
Components: Security
Reporter: Daniel John Debrunner
Increases security by providing less information to any attacker. The current
returned hash value could be used in an off-line dictionary based attack to
find a valid password.
--
This message is automatically generated by JIRA.
-
You can reply to this email to add a comment to the issue online.