Логотип exploitDog
bind:CVE-2020-26168
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-26168

Количество 3

Количество 3

nvd логотип

CVE-2020-26168

около 5 лет назад

The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, doesn't verify properly the password in some system-user-dn scenarios. As a result, users (clients/members) can be authenticated even if they provide invalid passwords.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2020-26168

около 5 лет назад

The LDAP authentication method in LdapLoginModule in Hazelcast IMDG En ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-whg4-vj5j-j9x2

больше 3 лет назад

The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, doesn't verify properly the password in some system-user-dn scenarios. As a result, users (clients/members) can be authenticated even if they provide invalid passwords.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-26168

The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, doesn't verify properly the password in some system-user-dn scenarios. As a result, users (clients/members) can be authenticated even if they provide invalid passwords.

CVSS3: 9.8
1%
Низкий
около 5 лет назад
debian логотип
CVE-2020-26168

The LDAP authentication method in LdapLoginModule in Hazelcast IMDG En ...

CVSS3: 9.8
1%
Низкий
около 5 лет назад
github логотип
GHSA-whg4-vj5j-j9x2

The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, doesn't verify properly the password in some system-user-dn scenarios. As a result, users (clients/members) can be authenticated even if they provide invalid passwords.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу