CVE Vulnerabilities

CVE-2012-5629

Published: Mar 12, 2013 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
7.5 IMPORTANT
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise Web Platform (EWP) 5.2.0 allow remote attackers to bypass authentication via an empty password.

Affected Software

Name Vendor Start Version End Version
Jboss_enterprise_application_platform Redhat 4.3.0 (including) 4.3.0 (including)
Jboss_enterprise_application_platform Redhat 5.2.0 (including) 5.2.0 (including)
Jboss_enterprise_application_platform Redhat 6.0.1 (including) 6.0.1 (including)
Jboss_enterprise_web_platform Redhat 5.2.0 (including) 5.2.0 (including)
JBEWP 5 for RHEL 5 RedHat jbosssx2-0:2.0.5-9.SP3_1_patch_01.ep5.el5 *
JBEWP 5 for RHEL 6 RedHat jbosssx2-0:2.0.5-9.1.SP3_1_patch_01.ep5.el6 *
JBoss Data Grid 6.1 RedHat *
JBoss Enterprise BRMS Platform 5.3 RedHat *
Red Hat JBoss Enterprise Application Platform 4.3 RedHat *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jbossas-0:4.3.0-12.GA_CP10_patch_01.1.ep1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jbossas-0:4.3.0-12.GA_CP10_patch_01.1.ep1.el5 *
Red Hat JBoss Enterprise Application Platform 5.2 RedHat *
Red Hat JBoss Enterprise Application Platform 5 for RHEL 4 RedHat jbosssx2-0:2.0.5-9.SP3_1_patch_01.ep5.el4 *
Red Hat JBoss Enterprise Application Platform 5 for RHEL 5 RedHat jbosssx2-0:2.0.5-9.SP3_1_patch_01.ep5.el5 *
Red Hat JBoss Enterprise Application Platform 5 for RHEL 6 RedHat jbosssx2-0:2.0.5-9.1.SP3_1_patch_01.ep5.el6 *
Red Hat JBoss Enterprise Application Platform 6.0 RedHat *
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5 RedHat jboss-as-domain-management-0:7.1.3-5.Final_redhat_5.ep6.el5 *
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5 RedHat picketbox-0:4.0.14-3.Final_redhat_3.ep6.el5 *
Red Hat JBoss Enterprise Application Platform 6 for RHEL 6 RedHat jboss-as-domain-management-0:7.1.3-5.Final_redhat_5.ep6.el6 *
Red Hat JBoss Enterprise Application Platform 6 for RHEL 6 RedHat picketbox-0:4.0.14-3.Final_redhat_3.ep6.el6 *
Red Hat JBoss Portal 4.3 RedHat *
Red Hat JBoss Portal 5.2 RedHat *
Red Hat JBoss SOA Platform 4.2 RedHat *
Red Hat JBoss SOA Platform 4.3 RedHat *
Red Hat JBoss SOA Platform 5.3 RedHat *
Red Hat JBoss SOA Platform 5.3 RedHat *
Red Hat JBoss Web Platform 5.2 RedHat *

References