CVE-2010-1596

Support Incident Tracker before 3.51, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sitracker:support_incident_tracker:*:*:*:*:*:*:*:*
cpe:2.3:a:sitracker:support_incident_tracker:3.21:*:*:*:*:*:*:*
cpe:2.3:a:sitracker:support_incident_tracker:3.22:*:*:*:*:*:*:*
cpe:2.3:a:sitracker:support_incident_tracker:3.22pl1:*:*:*:*:*:*:*
cpe:2.3:a:sitracker:support_incident_tracker:3.23:*:*:*:*:*:*:*
cpe:2.3:a:sitracker:support_incident_tracker:3.24:*:*:*:*:*:*:*
cpe:2.3:a:sitracker:support_incident_tracker:3.24:beta-2:*:*:*:*:*:*
cpe:2.3:a:sitracker:support_incident_tracker:3.30:*:*:*:*:*:*:*
cpe:2.3:a:sitracker:support_incident_tracker:3.30:beta2:*:*:*:*:*:*
cpe:2.3:a:sitracker:support_incident_tracker:3.31:*:*:*:*:*:*:*
cpe:2.3:a:sitracker:support_incident_tracker:3.32:*:*:*:*:*:*:*
cpe:2.3:a:sitracker:support_incident_tracker:3.33:*:*:*:*:*:*:*
cpe:2.3:a:sitracker:support_incident_tracker:3.35:*:*:*:*:*:*:*
cpe:2.3:a:sitracker:support_incident_tracker:3.35:beta1:*:*:*:*:*:*
cpe:2.3:a:sitracker:support_incident_tracker:3.36:*:*:*:*:*:*:*
cpe:2.3:a:sitracker:support_incident_tracker:3.40:*:*:*:*:*:*:*
cpe:2.3:a:sitracker:support_incident_tracker:3.40:beta1:*:*:*:*:*:*
cpe:2.3:a:sitracker:support_incident_tracker:3.41:*:*:*:*:*:*:*
cpe:2.3:a:sitracker:support_incident_tracker:3.45:*:*:*:*:*:*:*
cpe:2.3:a:sitracker:support_incident_tracker:3.45:beta1:*:*:*:*:*:*
cpe:2.3:a:sitracker:support_incident_tracker:3.50:beta1:*:*:*:*:*:*

History

21 Nov 2024, 01:14

Type Values Removed Values Added
References () http://bugs.sitracker.org/view.php?id=1047 - () http://bugs.sitracker.org/view.php?id=1047 -
References () http://osvdb.org/61945 - () http://osvdb.org/61945 -
References () http://secunia.com/advisories/38329 - Vendor Advisory () http://secunia.com/advisories/38329 - Vendor Advisory
References () http://sitracker.org/forum/viewtopic.php?f=4&t=1416979&p=2292 - () http://sitracker.org/forum/viewtopic.php?f=4&t=1416979&p=2292 -
References () http://sitracker.org/wiki/ReleaseNotes351 - Patch () http://sitracker.org/wiki/ReleaseNotes351 - Patch
References () http://www.securityfocus.com/bid/37949 - () http://www.securityfocus.com/bid/37949 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/55871 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/55871 -

Information

Published : 2010-04-28 23:30

Updated : 2024-11-21 01:14


NVD link : CVE-2010-1596

Mitre link : CVE-2010-1596

CVE.ORG link : CVE-2010-1596


JSON object : View

Products Affected

sitracker

  • support_incident_tracker
CWE
CWE-287

Improper Authentication