Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-5629

Опубликовано: 04 фев. 2013
Источник: redhat
CVSS2: 7.5
EPSS Низкий

Описание

The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise Web Platform (EWP) 5.2.0 allow remote attackers to bypass authentication via an empty password.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss BRMS 5jbosssxAffected
Red Hat JBoss Data Grid 6picketboxAffected
Red Hat JBoss Operations Network 3.1jbosssxNot affected
Red Hat JBoss Portal 4jbosssxAffected
Red Hat JBoss Portal 5jbosssxAffected
Red Hat JBoss SOA Platform 4.2jbosssxAffected
Red Hat JBoss SOA Platform 4.3jbosssxAffected
Red Hat JBoss SOA Platform 5jbosssxAffected
JBEWP 5 for RHEL 5jbosssx2FixedRHSA-2013:023004.02.2013
JBEWP 5 for RHEL 6jbosssx2FixedRHSA-2013:023004.02.2013

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20->CWE-305
https://bugzilla.redhat.com/show_bug.cgi?id=885569JBoss: allows empty password to authenticate against LDAP

EPSS

Процентиль: 73%
0.00788
Низкий

7.5 High

CVSS2

Связанные уязвимости

ubuntu
почти 13 лет назад

The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise Web Platform (EWP) 5.2.0 allow remote attackers to bypass authentication via an empty password.

nvd
почти 13 лет назад

The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise Web Platform (EWP) 5.2.0 allow remote attackers to bypass authentication via an empty password.

debian
почти 13 лет назад

The default configuration of the (1) LdapLoginModule and (2) LdapExtLo ...

github
больше 3 лет назад

The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise Web Platform (EWP) 5.2.0 allow remote attackers to bypass authentication via an empty password.

EPSS

Процентиль: 73%
0.00788
Низкий

7.5 High

CVSS2