CVE-2012-5629 PUBLISHED CVSS 7.5 HIGH

The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise Web Platform (EWP) 5.2.0 allow remote attackers to bypass authentication via an empty password.

EPSS 0.79% · 73.7th percentile

Risk Scores

CVSS v2.0
7.5
EPSS Score
0.79%
73.7th percentile

Affected Products

VendorProductVersions
redhatjboss_enterprise_application_platform4.3.0, 5.2.0, 6.0.1
n/an/an/a
redhatjboss_enterprise_web_platform5.2.0

Timeline

References

…and 4 more

Open in Interactive Console →