CVE Vulnerabilities

CVE-2012-5629

Published: Mar 12, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
7.5 IMPORTANT
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise Web Platform (EWP) 5.2.0 allow remote attackers to bypass authentication via an empty password.

Affected Software

NameVendorStart VersionEnd Version
Jboss_enterprise_application_platformRedhat4.3.0 (including)4.3.0 (including)
Jboss_enterprise_application_platformRedhat5.2.0 (including)5.2.0 (including)
Jboss_enterprise_application_platformRedhat6.0.1 (including)6.0.1 (including)
Jboss_enterprise_web_platformRedhat5.2.0 (including)5.2.0 (including)
JBEWP 5 for RHEL 5RedHatjbosssx2-0:2.0.5-9.SP3_1_patch_01.ep5.el5*
JBEWP 5 for RHEL 6RedHatjbosssx2-0:2.0.5-9.1.SP3_1_patch_01.ep5.el6*
JBoss Data Grid 6.1RedHat*
JBoss Enterprise BRMS Platform 5.3RedHat*
Red Hat JBoss Enterprise Application Platform 4.3RedHat*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatjbossas-0:4.3.0-12.GA_CP10_patch_01.1.ep1.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatjbossas-0:4.3.0-12.GA_CP10_patch_01.1.ep1.el5*
Red Hat JBoss Enterprise Application Platform 5.2RedHat*
Red Hat JBoss Enterprise Application Platform 5 for RHEL 4RedHatjbosssx2-0:2.0.5-9.SP3_1_patch_01.ep5.el4*
Red Hat JBoss Enterprise Application Platform 5 for RHEL 5RedHatjbosssx2-0:2.0.5-9.SP3_1_patch_01.ep5.el5*
Red Hat JBoss Enterprise Application Platform 5 for RHEL 6RedHatjbosssx2-0:2.0.5-9.1.SP3_1_patch_01.ep5.el6*
Red Hat JBoss Enterprise Application Platform 6.0RedHat*
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5RedHatjboss-as-domain-management-0:7.1.3-5.Final_redhat_5.ep6.el5*
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5RedHatpicketbox-0:4.0.14-3.Final_redhat_3.ep6.el5*
Red Hat JBoss Enterprise Application Platform 6 for RHEL 6RedHatjboss-as-domain-management-0:7.1.3-5.Final_redhat_5.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6 for RHEL 6RedHatpicketbox-0:4.0.14-3.Final_redhat_3.ep6.el6*
Red Hat JBoss Portal 4.3RedHat*
Red Hat JBoss Portal 5.2RedHat*
Red Hat JBoss SOA Platform 4.2RedHat*
Red Hat JBoss SOA Platform 4.3RedHat*
Red Hat JBoss SOA Platform 5.3RedHat*
Red Hat JBoss SOA Platform 5.3RedHat*
Red Hat JBoss Web Platform 5.2RedHat*

References