Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Oschlueter

#26392of 53,624
9.8Total CVSS
Vulnerabilities · 1
PT-2018-14432
9.8
2018-10-16
Neo4J · Neo4J Enterprise Database Server · CVE-2018-18389
**Name of the Vulnerable Software and Affected Versions** Neo4j Enterprise Database Server versions 3.4.x through 3.4.8 **Description** The issue arises from incorrect access control, allowing an attacker to log into the server by sending any valid username with an arbitrary password when LDAP is set for authentication with STARTTLS and System Account is used for authorization. **Recommendations** For Neo4j Enterprise Database Server versions 3.4.x through 3.4.8, update to version 3.4.9 or later to resolve the issue.