CVE-2012-1100
Severity
5.8MEDIUM
EPSS
0.3%
top 46.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 14
Latest updateMay 17
Description
Red Hat JBoss Operations Network (JON) 3.0.x before 3.0.1, 2.4.2, and earlier, when LDAP authentication is enabled and the LDAP bind account credentials are invalid, allows remote attackers to login to LDAP-based accounts via an arbitrary password in a login request.
CVSS vector
AV:N/AC:M/C:P/I:P/A:NExploitability: 8.6 | Impact: 4.9
Affected Packages1 packages
๐ดVulnerability Details
2๐ฅExploits & PoCs
1๐Vendor Advisories
1๐ฌCommunity
1Bugzillaโถ
CVE-2012-1100 JON: LDAP authentication allows any user access if bind credentials are badโ2012-03-05