CVE Vulnerabilities

CVE-2012-1100

Improper Authentication

Published: Feb 14, 2014 | Modified: Feb 14, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
5.8 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu

Red Hat JBoss Operations Network (JON) 3.0.x before 3.0.1, 2.4.2, and earlier, when LDAP authentication is enabled and the LDAP bind account credentials are invalid, allows remote attackers to login to LDAP-based accounts via an arbitrary password in a login request.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Jboss_operations_network Redhat * 2.4.1 (including)
Jboss_operations_network Redhat 2.0.0 (including) 2.0.0 (including)
Jboss_operations_network Redhat 2.0.1 (including) 2.0.1 (including)
Jboss_operations_network Redhat 2.1.0 (including) 2.1.0 (including)
Jboss_operations_network Redhat 2.2 (including) 2.2 (including)
Jboss_operations_network Redhat 2.3 (including) 2.3 (including)
Jboss_operations_network Redhat 2.3.1 (including) 2.3.1 (including)
Jboss_operations_network Redhat 2.4 (including) 2.4 (including)
Jboss_operations_network Redhat 3.0 (including) 3.0 (including)
Red Hat JBoss Operations Network 2.4 RedHat *
Red Hat JBoss Operations Network 3.0 RedHat *

Potential Mitigations

References