CVE-2012-1100
Summary
| CVE | CVE-2012-1100 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-02-14 15:55:04 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Red Hat JBoss Operations Network (JON) 3.0.x before 3.0.1, 2.4.2, and earlier, when LDAP authentication is enabled and the LDAP bind account credentials are invalid, allows remote attackers to login to LDAP-based accounts via an arbitrary password in a login request. |
Risk And Classification
Primary CVSS: v2.0 5.8 from [email protected]
AV:N/AC:M/Au:N/C:P/I:P/A:N
EPSS: 0.003050000 probability, percentile 0.536540000 (date 2026-05-05)
Problem Types: CWE-287 | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Jboss Operations Network | 2.0.0 | All | All | All |
| Application | Redhat | Jboss Operations Network | 2.0.1 | All | All | All |
| Application | Redhat | Jboss Operations Network | 2.1.0 | All | All | All |
| Application | Redhat | Jboss Operations Network | 2.2 | All | All | All |
| Application | Redhat | Jboss Operations Network | 2.3 | All | All | All |
| Application | Redhat | Jboss Operations Network | 2.3.1 | All | All | All |
| Application | Redhat | Jboss Operations Network | 2.4 | All | All | All |
| Application | Redhat | Jboss Operations Network | 3.0 | All | All | All |
| Application | Redhat | Jboss Operations Network | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| rhn.redhat.com/errata/RHSA-2012-0396.html | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Vendor Advisory |
| rhn.redhat.com/errata/RHSA-2012-0406.html | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Vendor Advisory |
| 799789 – (CVE-2012-1100) CVE-2012-1100 JON: LDAP authentication allows any user access if bind credentials are bad | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.