CVE-2012-5629
12.03.2013, 23:55
The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise Web Platform (EWP) 5.2.0 allow remote attackers to bypass authentication via an empty password.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | jboss_enterprise_application_platform | 4.3.0 |
redhat | jboss_enterprise_application_platform | 5.2.0 |
redhat | jboss_enterprise_application_platform | 6.0.1 |
redhat | jboss_enterprise_web_platform | 5.2.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References