PT-2018-5384 · Libpam4J · Libpam4J

Published

2017-11-08

·

Updated

2022-05-13

·

CVE-2017-12197

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: libpam4j versions prior to 1.10
Description: The issue arises from improper validation of user accounts during authentication. Specifically, a user with a valid password for a disabled account can bypass security restrictions, potentially accessing sensitive information.
Recommendations: For versions prior to 1.10, update to version 1.10 or later to resolve the issue. As a temporary workaround, consider restricting access to disabled accounts to minimize the risk of exploitation.

Fix

RCE

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-12197
DLA-1165-1
DSA-4025-1
GHSA-X9RG-Q5FX-FX66
MGASA-2018-0234
RHSA-2017:2904
RHSA-2017:2905

Affected Products

Libpam4J