PT-2015-1320 · Emc · Emc Unified Infrastructure Manager/Provisioning
Published
2015-06-17
·
Updated
2017-09-23
·
CVE-2015-0546
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
EMC Unified Infrastructure Manager/Provisioning (UIM/P) version 4.1
Description
The issue exists due to an error in the access control subsystem, allowing a remote attacker to bypass the authentication procedure via the LDAP service by providing only a valid user account name.
Recommendations
For version 4.1, consider restricting access to the LDAP authentication service until a patch is available. As a temporary workaround, limit the use of the vulnerable authentication mechanism to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Emc Unified Infrastructure Manager/Provisioning