Описание
The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind. NOTE: this identifier has been SPLIT per ADT2 due to different vulnerability types. See CVE-2015-6524 for the use of wildcard operators in usernames.
It was found that if a configured LDAP server supported the unauthenticated authentication mechanism (as described by RFC 4513), the LDAPLoginModule implementation, provided by ActiveMQ Java Authentication and Authorization Service (JAAS), would consider an authentication attempt to be successful for a valid user that provided an empty password. A remote attacker could use this flaw to bypass the authentication mechanism of an application using LDAPLoginModule, and assume a role of any valid user within that application.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Enterprise 1 | activemq | Will not fix | ||
| Red Hat JBoss Enterprise Web Server 1 | amq-6 | Affected | ||
| Red Hat JBoss Enterprise Web Server 1 | fuse-mq-5.4 | Will not fix | ||
| Red Hat JBoss Enterprise Web Server 1 | fuse-mq-5.5 | Affected | ||
| Red Hat JBoss Enterprise Web Server 1 | fuse-mq-7 | Affected | ||
| Red Hat JBoss Enterprise Web Server 1 | others | Not affected | ||
| Red Hat OpenShift Enterprise 2 | activemq | Will not fix | ||
| Fuse ESB Enterprise 7.1.0 | Fixed | RHSA-2015:0138 | 05.02.2015 | |
| Fuse Management Console 7.1.0 | Fixed | RHSA-2015:0138 | 05.02.2015 | |
| Fuse MQ Enterprise 7.1.0 | Fixed | RHSA-2015:0138 | 05.02.2015 |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS2
Связанные уязвимости
The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind. NOTE: this identifier has been SPLIT per ADT2 due to different vulnerability types. See CVE-2015-6524 for the use of wildcard operators in usernames.
The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind. NOTE: this identifier has been SPLIT per ADT2 due to different vulnerability types. See CVE-2015-6524 for the use of wildcard operators in usernames.
The LDAPLoginModule implementation in the Java Authentication and Auth ...
Уязвимость программной платформы Apache ActiveMQ, позволяющая нарушителю обойти процедуру аутентификации
7.5 High
CVSS2