CVE-2014-0097
25.05.2017, 17:29
The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty password.Enginsight
| Vendor | Product | Version |
|---|---|---|
| vmware | spring_security | 3.1.0 |
| vmware | spring_security | 3.1.1 |
| vmware | spring_security | 3.1.2 |
| vmware | spring_security | 3.1.3 |
| vmware | spring_security | 3.1.4 |
| vmware | spring_security | 3.1.5 |
| vmware | spring_security | 3.2.0 |
| vmware | spring_security | 3.2.1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration