CVE-2014-0097
25.05.2017, 17:29
The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty password.Enginsight
Vendor | Product | Version |
---|---|---|
vmware | spring_security | 3.1.0 |
vmware | spring_security | 3.1.1 |
vmware | spring_security | 3.1.2 |
vmware | spring_security | 3.1.3 |
vmware | spring_security | 3.1.4 |
vmware | spring_security | 3.1.5 |
vmware | spring_security | 3.2.0 |
vmware | spring_security | 3.2.1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration