Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-8750

Опубликовано: 19 фев. 2018
Источник: nvd
CVSS3: 6.5
CVSS2: 4
EPSS Низкий

Описание

Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not encoding usernames properly and hence was vulnerable to LDAP injection attacks leading to a denial of service.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:karaf:*:*:*:*:*:*:*:*
Версия до 4.0.8 (исключая)

EPSS

Процентиль: 81%
0.0151
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-90

Связанные уязвимости

CVSS3: 7.5
redhat
около 9 лет назад

Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not encoding usernames properly and hence was vulnerable to LDAP injection attacks leading to a denial of service.

CVSS3: 6.5
debian
почти 8 лет назад

Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate u ...

CVSS3: 6.5
github
около 7 лет назад

Moderate severity vulnerability that affects org.apache.karaf:apache-karaf

EPSS

Процентиль: 81%
0.0151
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-90