cbcvebase.
CVE-2017-12197
published 2018-01-18

CVE-2017-12197: It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a disabled…

PriorityP335medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
1.51%
71.8th percentile
It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a disabled account would be able to bypass security restrictions and possibly access sensitive information.

Affected

41 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
jenkinsarachni_scanner_plugin
jenkinsargus_notifier_plugin
jenkinsartifactory_plugin
jenkinschatter_notifier_plugin
jenkinsconfig_file_provider_plugin
jenkinscredentials_plugin
jenkinscrowd_2_integration_plugin
jenkinsdimensions_plugin
jenkinsemail_extension_template_plugin
jenkinsgit_changelog_plugin
jenkinshipchat_plugin
jenkinsids_in_argus_notifier_plugin
jenkinsids_in_chatter_notifier_plugin
jenkinsids_in_hipchat_plugin
jenkinsids_in_mesos_plugin
jenkinsids_to_allow_administrators_configuring_the_plugin
jenkinsids_to_allow_users_configuring_the_plugin
jenkinsjavamelody_library_bundled_in_monitoring_plugin
jenkinsjira_plugin
jenkinsjob_config_history_plugin
jenkinsjob_configuration_history_plugin
jenkinsjunit_plugin

CVSS provenance

nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.