Lucene search

K
cve[email protected]CVE-2012-5629
HistoryMar 12, 2013 - 11:55 p.m.

CVE-2012-5629

2013-03-1223:55:01
CWE-264
web.nvd.nist.gov
23
jboss
eap
ewp
ldaploginmodule
ldapextloginmodule
authentication bypass
empty password
cve-2012-5629

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

5.7 Medium

AI Score

Confidence

High

0.014 Low

EPSS

Percentile

86.2%

The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise Web Platform (EWP) 5.2.0 allow remote attackers to bypass authentication via an empty password.

Affected configurations

NVD
Node
redhatjboss_enterprise_application_platformMatch4.3.0
OR
redhatjboss_enterprise_application_platformMatch5.2.0
OR
redhatjboss_enterprise_application_platformMatch6.0.1
OR
redhatjboss_enterprise_web_platformMatch5.2.0

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

5.7 Medium

AI Score

Confidence

High

0.014 Low

EPSS

Percentile

86.2%