PT-2023-20159 · Oracle · Java Authentication/Authorization Service

Jorgectf

+4

·

Published

2023-02-10

·

Updated

2025-12-03

·

CVE-2023-25561

CVSS v3.1

5.7

Medium

VectorAV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions DataHub (affected versions not specified)
Description The issue occurs when a system using Java Authentication and Authorization Service (JAAS) authentication encounters a configuration error, causing authentication to fail open. This allows an attacker to login with any username and password due to an error being thrown in the authenticateJaasUser method but not propagated. As a result, unauthenticated users may gain access to the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Handling of Exceptional Conditions

Weakness Enumeration

Related Identifiers

CVE-2023-25561
GHSA-7WC6-P6C4-522C

Affected Products

Java Authentication/Authorization Service