CVE-2014-6632: High severity joomla vulnerability
Published Oct 8, 2014
·Updated
Joomla! 2.5.x before 2.5.25, 3.x before 3.2.4, and 3.3.x before 3.3.4 allows remote attackers to authenticate and bypass intended access restrictions via vectors involving LDAP authentication.
Affected Software
32 affected components
Joomla Joomla\!=2.5.0
Joomla Joomla\!=2.5.1
Joomla Joomla\!=2.5.2
Joomla Joomla\!=2.5.3
Joomla Joomla\!=2.5.4
Joomla Joomla\!=2.5.5
Joomla Joomla\!=2.5.6
Joomla Joomla\!=2.5.7
Joomla Joomla\!=2.5.8
Joomla Joomla\!=2.5.9
Joomla Joomla\!=2.5.10
Joomla Joomla\!=2.5.11
Joomla Joomla\!=2.5.12
Joomla Joomla\!=2.5.13
Joomla Joomla\!=2.5.14
Joomla Joomla\!=2.5.15
Joomla Joomla\!=2.5.16
Joomla Joomla\!=2.5.17
Joomla Joomla\!=2.5.19
Joomla Joomla\!=2.5.20
Joomla Joomla\!=2.5.21
Joomla Joomla\!=2.5.22
Joomla Joomla\!=2.5.23
Joomla Joomla\!=2.5.24
Joomla Joomla\!=3.2.0
Joomla Joomla\!=3.2.1
Joomla Joomla\!=3.2.2
Joomla Joomla\!=3.2.3
Joomla Joomla\!=3.3.0
Joomla Joomla\!=3.3.1
Joomla Joomla\!=3.3.2
Joomla Joomla\!=3.3.3
Event History
Oct 8, 2014
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-6632?
CVE-2014-6632 has a medium severity rating as it allows for unauthorized access through LDAP authentication bypass.
2
How do I fix CVE-2014-6632?
To fix CVE-2014-6632, upgrade Joomla to version 2.5.25 or later, or 3.2.4 or later.
3
What versions of Joomla are affected by CVE-2014-6632?
CVE-2014-6632 affects Joomla versions 2.5.x before 2.5.25, 3.x before 3.2.4, and 3.3.x before 3.3.4.
4
Can CVE-2014-6632 be exploited remotely?
Yes, CVE-2014-6632 can be exploited remotely by attackers who attempt to authenticate and bypass access restrictions.
5
What are the impacts of CVE-2014-6632?
The impact of CVE-2014-6632 includes unauthorized access to sensitive data and user accounts within affected Joomla installations.