PT-2015-1320 · Emc · Emc Unified Infrastructure Manager/Provisioning

Published

2015-06-17

·

Updated

2017-09-23

·

CVE-2015-0546

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions EMC Unified Infrastructure Manager/Provisioning (UIM/P) version 4.1
Description The issue exists due to an error in the access control subsystem, allowing a remote attacker to bypass the authentication procedure via the LDAP service by providing only a valid user account name.
Recommendations For version 4.1, consider restricting access to the LDAP authentication service until a patch is available. As a temporary workaround, limit the use of the vulnerable authentication mechanism to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-10388
CVE-2015-0546

Affected Products

Emc Unified Infrastructure Manager/Provisioning