PT-2018-5384 · Libpam4J · Libpam4J

Publicado

2017-11-08

·

Atualizado

2022-05-13

·

CVE-2017-12197

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: libpam4j versions prior to 1.10
Description: The issue arises from improper validation of user accounts during authentication. Specifically, a user with a valid password for a disabled account can bypass security restrictions, potentially accessing sensitive information.
Recommendations: For versions prior to 1.10, update to version 1.10 or later to resolve the issue. As a temporary workaround, consider restricting access to disabled accounts to minimize the risk of exploitation.

Correção

RCE

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-12197
DLA-1165-1
DSA-4025-1
GHSA-X9RG-Q5FX-FX66
MGASA-2018-0234
RHSA-2017:2904
RHSA-2017:2905

Produtos afetados

Libpam4J