PT-2018-5384 · Libpam4J · Libpam4J
Published
2017-11-08
·
Updated
2022-05-13
·
CVE-2017-12197
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
libpam4j versions prior to 1.10
Description:
The issue arises from improper validation of user accounts during authentication. Specifically, a user with a valid password for a disabled account can bypass security restrictions, potentially accessing sensitive information.
Recommendations:
For versions prior to 1.10, update to version 1.10 or later to resolve the issue. As a temporary workaround, consider restricting access to disabled accounts to minimize the risk of exploitation.
Fix
RCE
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Libpam4J