Apache Shiro 1.x before 1.2.3, when using an LDAP server with unauthenticated bind enabled, allows remote attackers to bypass authentication via an empty (1) username or (2) password.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Shiro | Apache | 1.0.0 (including) | 1.0.0 (including) |
Shiro | Apache | 1.1.0 (including) | 1.1.0 (including) |
Shiro | Apache | 1.2.0 (including) | 1.2.0 (including) |
Shiro | Apache | 1.2.1 (including) | 1.2.1 (including) |
Shiro | Apache | 1.2.2 (including) | 1.2.2 (including) |
Fuse ESB Enterprise 7.1.0 | RedHat | * | |
Fuse Management Console 7.1.0 | RedHat | * | |
Fuse MQ Enterprise 7.1.0 | RedHat | * | |
Red Hat JBoss A-MQ 6.1 | RedHat | * | |
Red Hat JBoss Fuse 6.1 | RedHat | * |