CVE-2012-1100
Published Feb 14, 2014
Last updated 11 years ago
Overview
- Description
- Red Hat JBoss Operations Network (JON) 3.0.x before 3.0.1, 2.4.2, and earlier, when LDAP authentication is enabled and the LDAP bind account credentials are invalid, allows remote attackers to login to LDAP-based accounts via an arbitrary password in a login request.
- Source
- secalert@redhat.com
- NVD status
- Analyzed
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5.8
- Impact score
- 4.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-287
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:redhat:jboss_operations_network:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "87E50BCC-4B27-43F7-8AB3-EC27297C4B2C", "versionEndIncluding": "2.4.1" }, { "criteria": "cpe:2.3:a:redhat:jboss_operations_network:2.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D29DC3CE-E782-47F7-BDF4-4AB63728F05B" }, { "criteria": "cpe:2.3:a:redhat:jboss_operations_network:2.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DF4A10F6-2128-4986-8A28-BD9B679D8380" }, { "criteria": "cpe:2.3:a:redhat:jboss_operations_network:2.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3B720DED-23EE-4830-9C8B-441A38DAE80E" }, { "criteria": "cpe:2.3:a:redhat:jboss_operations_network:2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0FD44168-A91A-4043-8C34-7A20DC2C1A19" }, { "criteria": "cpe:2.3:a:redhat:jboss_operations_network:2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "66926B59-4A4F-47B9-9B2B-3D8DC698BC97" }, { "criteria": "cpe:2.3:a:redhat:jboss_operations_network:2.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D72DFB62-EEA6-4126-9DC3-B191CC8D0CA5" }, { "criteria": "cpe:2.3:a:redhat:jboss_operations_network:2.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B8DBE132-2A98-40C6-947F-50C1D06DDFB1" }, { "criteria": "cpe:2.3:a:redhat:jboss_operations_network:3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C077D692-150C-4AE9-8C0B-7A3EA5EB1100" } ], "operator": "OR" } ] } ]