CVE-2012-5629
published 2013-03-12CVE-2012-5629: The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and…
PriorityP347high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.34%
81.7th percentile
The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise Web Platform (EWP) 5.2.0 allow remote attackers to bypass authentication via an empty password.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_web_platform | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
JBoss: allows empty password to authenticate against LDAP
vendor_redhat·2013-02-04·CVSS 7.5
CVE-2012-5629 [HIGH] CWE-20 JBoss: allows empty password to authenticate against LDAP
JBoss: allows empty password to authenticate against LDAP
The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise Web Platform (EWP) 5.2.0 allow remote attackers to bypass authentication via an empty password.
Package: jbosssx (Red Hat JBoss BRMS 5) - Affected
Package: picketbox (Red Hat JBoss Data Grid 6) - Affected
Package: jbosssx (Red Hat JBoss Operations Network 3.1) - Not affected
Package: jbosssx (Red Hat JBoss Portal 4) - Affected
Package: jbosssx (Red Hat JBoss Portal 5) - Affected
Package: jbosssx (Red Hat JBoss SOA Platform 4.2) - Affected
Package: jbosssx (Red Hat JBoss SOA Platform 4.3) - Affected
Package: jbosssx (Red Hat JBoss SOA Platform 5) -
GHSA
GHSA-m4f6-9xf8-2whr: The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4
ghsa_unreviewed·2022-05-17
CVE-2012-5629 [HIGH] GHSA-m4f6-9xf8-2whr: The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4
The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise Web Platform (EWP) 5.2.0 allow remote attackers to bypass authentication via an empty password.
No detection rules found.
No public exploits indexed.
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=885569http://rhn.redhat.com/errata/RHSA-2013-0229.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0230.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0231.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0232.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0233.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0234.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0248.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0533.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0586.htmlhttp://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=885569http://rhn.redhat.com/errata/RHSA-2013-0229.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0230.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0231.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0232.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0233.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0234.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0248.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0533.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0586.html
2013-03-12
Published