CVE-2012-5629: High severity jboss enterprise application platform vulnerability
The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise Web Platform (EWP) 5.2.0 allow remote attackers to bypass authentication via an empty password.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5629?
CVE-2012-5629 has a medium severity rating due to its potential to allow remote attackers to bypass authentication.
How do I fix CVE-2012-5629?
To fix CVE-2012-5629, update your JBoss Enterprise Application Platform or Enterprise Web Platform to a patched version that addresses this vulnerability.
Which versions of JBoss are affected by CVE-2012-5629?
CVE-2012-5629 affects JBoss Enterprise Application Platform versions 4.3.0, 5.2.0, 6.0.1, and JBoss Enterprise Web Platform version 5.2.0.
Can CVE-2012-5629 be exploited without authentication?
Yes, CVE-2012-5629 can be exploited by remote attackers who can bypass authentication with an empty password.
What components are involved in CVE-2012-5629?
CVE-2012-5629 involves the LdapLoginModule and LdapExtLoginModule components in JBoss.