Vulnerability CVE-2014-0074


Published: 2014-10-06

Description:
Apache Shiro 1.x before 1.2.3, when using an LDAP server with unauthenticated bind enabled, allows remote attackers to bypass authentication via an empty (1) username or (2) password.

See advisories in our WLB2 database:
Topic
Author
Date
High
Apache Shiro 1.2.2 LDAP Authentication Bypass
The Apache Shiro...
05.03.2014

Type:

CWE-287

(Improper Authentication)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Apache -> Shiro 

 References:
https://issues.apache.org/jira/browse/SHIRO-460
http://seclists.org/fulldisclosure/2014/Mar/22
http://rhn.redhat.com/errata/RHSA-2014-1351.html

Copyright 2024, cxsecurity.com

 

Back to Top