Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3612

Опубликовано: 05 фев. 2015
Источник: redhat
CVSS2: 7.5

Описание

The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind. NOTE: this identifier has been SPLIT per ADT2 due to different vulnerability types. See CVE-2015-6524 for the use of wildcard operators in usernames.

It was found that if a configured LDAP server supported the unauthenticated authentication mechanism (as described by RFC 4513), the LDAPLoginModule implementation, provided by ActiveMQ Java Authentication and Authorization Service (JAAS), would consider an authentication attempt to be successful for a valid user that provided an empty password. A remote attacker could use this flaw to bypass the authentication mechanism of an application using LDAPLoginModule, and assume a role of any valid user within that application.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Enterprise 1activemqWill not fix
Red Hat JBoss Enterprise Web Server 1amq-6Affected
Red Hat JBoss Enterprise Web Server 1fuse-mq-5.4Will not fix
Red Hat JBoss Enterprise Web Server 1fuse-mq-5.5Affected
Red Hat JBoss Enterprise Web Server 1fuse-mq-7Affected
Red Hat JBoss Enterprise Web Server 1othersNot affected
Red Hat OpenShift Enterprise 2activemqWill not fix
Fuse ESB Enterprise 7.1.0FixedRHSA-2015:013805.02.2015
Fuse Management Console 7.1.0FixedRHSA-2015:013805.02.2015
Fuse MQ Enterprise 7.1.0FixedRHSA-2015:013805.02.2015

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20->CWE-305
https://bugzilla.redhat.com/show_bug.cgi?id=1135912JAAS: LDAPLoginModule allows empty password authentication

7.5 High

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind. NOTE: this identifier has been SPLIT per ADT2 due to different vulnerability types. See CVE-2015-6524 for the use of wildcard operators in usernames.

nvd
больше 10 лет назад

The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind. NOTE: this identifier has been SPLIT per ADT2 due to different vulnerability types. See CVE-2015-6524 for the use of wildcard operators in usernames.

debian
больше 10 лет назад

The LDAPLoginModule implementation in the Java Authentication and Auth ...

github
больше 3 лет назад

Improper Authentication in Apache WSS4J

fstec
больше 10 лет назад

Уязвимость программной платформы Apache ActiveMQ, позволяющая нарушителю обойти процедуру аутентификации

7.5 High

CVSS2