CVE Vulnerabilities

CVE-2012-5629

Published: Mar 12, 2013 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise Web Platform (EWP) 5.2.0 allow remote attackers to bypass authentication via an empty password.

Affected Software

Name Vendor Start Version End Version
Jboss_enterprise_application_platform Redhat 4.3.0 (including) 4.3.0 (including)
Jboss_enterprise_application_platform Redhat 5.2.0 (including) 5.2.0 (including)
Jboss_enterprise_application_platform Redhat 6.0.1 (including) 6.0.1 (including)
Jboss_enterprise_web_platform Redhat 5.2.0 (including) 5.2.0 (including)

References