PT-2008-1674 · Dbmail+1 · Dbmail+1

Vugluskr

·

Publicado

2008-04-17

·

Atualizado

2017-08-08

·

CVE-2007-6714

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions DBMail versions prior to 2.2.9
Description The issue allows remote attackers to bypass authentication by providing an empty password when using authldap with an LDAP server that supports anonymous login, such as Active Directory. This is because the LDAP bind indicates success based on anonymous authentication.
Recommendations For DBMail versions prior to 2.2.9, update to version 2.2.9 or later to resolve the issue. As a temporary workaround, consider disabling the use of authldap with LDAP servers that support anonymous login until a patch is applied. Restrict access to the LDAP authentication mechanism to minimize the risk of exploitation. Avoid using empty passwords in the affected authentication process until the issue is resolved.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-6714

Produtos afetados

Active Directory
Dbmail