CVE-2019-11187
15.08.2019, 17:15
Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to log into any account with a username containing the case-insensitive substring "success" when an arbitrary password is provided.Enginsight
| Vendor | Product | Version |
|---|---|---|
| gonicus | gosa | 𝑥 ≤ 2019-04-11 |
| debian | debian_linux | 8.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| fusiondirectory |
| ||||||||||||||||||||||||||||
| gosa |
|
Common Weakness Enumeration