PT-2018-14432 · Neo4J · Neo4J Enterprise Database Server
Oschlueter
·
Published
2018-10-16
·
Updated
2019-01-18
·
CVE-2018-18389
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Neo4j Enterprise Database Server versions 3.4.x through 3.4.8
Description
The issue arises from incorrect access control, allowing an attacker to log into the server by sending any valid username with an arbitrary password when LDAP is set for authentication with STARTTLS and System Account is used for authorization.
Recommendations
For Neo4j Enterprise Database Server versions 3.4.x through 3.4.8, update to version 3.4.9 or later to resolve the issue.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Neo4J Enterprise Database Server