The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty password.
References
Link | Resource |
---|---|
https://pivotal.io/security/cve-2014-0097 | Vendor Advisory |
https://www.oracle.com/security-alerts/cpuapr2022.html |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: dell
Published: 2017-05-25T17:00:00
Updated: 2022-04-19T23:19:11
Reserved: 2013-12-03T00:00:00
Link: CVE-2014-0097
JSON object: View
NVD Information
Status : Modified
Published: 2017-05-25T17:29:00.160
Modified: 2022-04-20T00:15:14.473
Link: CVE-2014-0097
JSON object: View
Redhat Information
No data.
CWE