CVE-2012-5629
Description
The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise Web Platform (EWP) 5.2.0 allow remote attackers to bypass authentication via an empty password.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — http://rhn.redhat.com/errata/RHSA-2013-0248.html
Vendor advisory: secalert@redhat.com — http://rhn.redhat.com/errata/RHSA-2013-0234.html
Vendor advisory: secalert@redhat.com — http://rhn.redhat.com/errata/RHSA-2013-0233.html
Vendor advisory: secalert@redhat.com — http://rhn.redhat.com/errata/RHSA-2013-0232.html
Vendor advisory: secalert@redhat.com — http://rhn.redhat.com/errata/RHSA-2013-0231.html
Vendor advisory: secalert@redhat.com — http://rhn.redhat.com/errata/RHSA-2013-0230.html
Vendor advisory: secalert@redhat.com — http://rhn.redhat.com/errata/RHSA-2013-0229.html
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | 4.3.0 | |
| redhat | jboss_enterprise_application_platform | 5.2.0 | |
| redhat | jboss_enterprise_application_platform | 6.0.1 | |
| redhat | jboss_enterprise_web_platform | 5.2.0 | |
References
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=885569
- http://rhn.redhat.com/errata/RHSA-2013-0229.html
- http://rhn.redhat.com/errata/RHSA-2013-0230.html
- http://rhn.redhat.com/errata/RHSA-2013-0231.html
- http://rhn.redhat.com/errata/RHSA-2013-0232.html
- http://rhn.redhat.com/errata/RHSA-2013-0233.html
- http://rhn.redhat.com/errata/RHSA-2013-0234.html
- http://rhn.redhat.com/errata/RHSA-2013-0248.html
- http://rhn.redhat.com/errata/RHSA-2013-0533.html
- http://rhn.redhat.com/errata/RHSA-2013-0586.html
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=885569
- http://rhn.redhat.com/errata/RHSA-2013-0229.html
- http://rhn.redhat.com/errata/RHSA-2013-0230.html
- http://rhn.redhat.com/errata/RHSA-2013-0231.html
- http://rhn.redhat.com/errata/RHSA-2013-0232.html
- http://rhn.redhat.com/errata/RHSA-2013-0233.html
- http://rhn.redhat.com/errata/RHSA-2013-0234.html
- http://rhn.redhat.com/errata/RHSA-2013-0248.html
- http://rhn.redhat.com/errata/RHSA-2013-0533.html
- http://rhn.redhat.com/errata/RHSA-2013-0586.html
CWEs
CWE-264
Verify integrity in audit chain (admin only). AS-IS.