CVE-2012-1100

Red Hat JBoss Operations Network (JON) 3.0.x before 3.0.1, 2.4.2, and earlier, when LDAP authentication is enabled and the LDAP bind account credentials are invalid, allows remote attackers to login to LDAP-based accounts via an arbitrary password in a login request.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:jboss_operations_network:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_operations_network:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_operations_network:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_operations_network:2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_operations_network:2.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_operations_network:2.3:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_operations_network:2.3.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_operations_network:2.4:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_operations_network:3.0:*:*:*:*:*:*:*

History

21 Nov 2024, 01:36

Type Values Removed Values Added
References () http://rhn.redhat.com/errata/RHSA-2012-0396.html - Vendor Advisory () http://rhn.redhat.com/errata/RHSA-2012-0396.html - Vendor Advisory
References () http://rhn.redhat.com/errata/RHSA-2012-0406.html - Vendor Advisory () http://rhn.redhat.com/errata/RHSA-2012-0406.html - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=799789 - () https://bugzilla.redhat.com/show_bug.cgi?id=799789 -

Information

Published : 2014-02-14 15:55

Updated : 2024-11-21 01:36


NVD link : CVE-2012-1100

Mitre link : CVE-2012-1100

CVE.ORG link : CVE-2012-1100


JSON object : View

Products Affected

redhat

  • jboss_operations_network
CWE
CWE-287

Improper Authentication