CVE-2012-5629
EUVD-2012-551412.03.2013, 23:55
The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise Web Platform (EWP) 5.2.0 allow remote attackers to bypass authentication via an empty password.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| redhat | jboss_enterprise_application_platform | 4.3.0 |
| redhat | jboss_enterprise_application_platform | 5.2.0 |
| redhat | jboss_enterprise_application_platform | 6.0.1 |
| redhat | jboss_enterprise_web_platform | 5.2.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration
References