First published: Mon Mar 05 2012(Updated: )
If JON is configured to use LDAP authentication, and the LDAP bind account credentials are invalid, any subsequent login attempt by a user created via LDAP will be successful with any arbitrary password.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat JBoss Operations Network | <=2.4.1 | |
Red Hat JBoss Operations Network | =2.0.0 | |
Red Hat JBoss Operations Network | =2.0.1 | |
Red Hat JBoss Operations Network | =2.1.0 | |
Red Hat JBoss Operations Network | =2.2 | |
Red Hat JBoss Operations Network | =2.3 | |
Red Hat JBoss Operations Network | =2.3.1 | |
Red Hat JBoss Operations Network | =2.4 | |
Red Hat JBoss Operations Network | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-1100 has been rated as a high-severity vulnerability due to its potential to allow unauthorized access.
To fix CVE-2012-1100, users should upgrade to JBoss Operations Network versions 3.0.1 or later, or any version above the affected versions listed.
CVE-2012-1100 specifically affects environments configured to use LDAP authentication.
Exploitation of CVE-2012-1100 allows an attacker to gain unauthorized access by logging in with any password after an invalid LDAP bind occurs.
Affected versions include JBoss Operations Network 2.4.1 and earlier, as well as versions 2.0.0 through 2.4, and 3.0 up to but not including 3.0.1.