The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise Web Platform (EWP) 5.2.0 allow remote attackers to bypass authentication via an empty password.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:45
Type | Values Removed | Values Added |
---|---|---|
References | () http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=885569 - | |
References | () http://rhn.redhat.com/errata/RHSA-2013-0229.html - Vendor Advisory | |
References | () http://rhn.redhat.com/errata/RHSA-2013-0230.html - Vendor Advisory | |
References | () http://rhn.redhat.com/errata/RHSA-2013-0231.html - Vendor Advisory | |
References | () http://rhn.redhat.com/errata/RHSA-2013-0232.html - Vendor Advisory | |
References | () http://rhn.redhat.com/errata/RHSA-2013-0233.html - Vendor Advisory | |
References | () http://rhn.redhat.com/errata/RHSA-2013-0234.html - Vendor Advisory | |
References | () http://rhn.redhat.com/errata/RHSA-2013-0248.html - Vendor Advisory | |
References | () http://rhn.redhat.com/errata/RHSA-2013-0533.html - | |
References | () http://rhn.redhat.com/errata/RHSA-2013-0586.html - |
Information
Published : 2013-03-12 23:55
Updated : 2024-11-21 01:45
NVD link : CVE-2012-5629
Mitre link : CVE-2012-5629
CVE.ORG link : CVE-2012-5629
JSON object : View
Products Affected
redhat
- jboss_enterprise_application_platform
- jboss_enterprise_web_platform
CWE
CWE-264
Permissions, Privileges, and Access Controls