PT-2023-20159 · Oracle · Java Authentication/Authorization Service

Jorgectf

+4

·

Publicado

2023-02-10

·

Atualizado

2025-12-03

·

CVE-2023-25561

CVSS v3.1

5.7

Média

VetorAV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions DataHub (affected versions not specified)
Description The issue occurs when a system using Java Authentication and Authorization Service (JAAS) authentication encounters a configuration error, causing authentication to fail open. This allows an attacker to login with any username and password due to an error being thrown in the authenticateJaasUser method but not propagated. As a result, unauthenticated users may gain access to the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Handling of Exceptional Conditions

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-25561
GHSA-7WC6-P6C4-522C

Produtos afetados

Java Authentication/Authorization Service