UnboundID LDAP SDK for Java CVE-2018-1000134 Authentication Bypass Vulnerability
BID:103458
CVE-2018-1000134 |Info
UnboundID LDAP SDK for Java CVE-2018-1000134 Authentication Bypass Vulnerability
| Bugtraq ID: | 103458 |
| Class: | Design Error |
| CVE: |
CVE-2018-1000134 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 16 2018 12:00AM |
| Updated: | Mar 16 2018 12:00AM |
| Credit: | NEIL WILSON |
| Vulnerable: |
UnboundID LDAP SDK for Java 4.0.4 |
| Not Vulnerable: |
UnboundID LDAP SDK for Java 4.0.5 |
Solution / Fix
UnboundID LDAP SDK for Java CVE-2018-1000134 Authentication Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
UnboundID LDAP SDK for Java CVE-2018-1000134 Authentication Bypass Vulnerability
References:
References:
- Bug 1557531 - (CVE-2018-1000134) CVE-2018-1000134 unboundid-ldapsdk: Incorrect A (Redhat)
- CVE-2018-1000134 (Redhat)
- CVE-2018-1000134 and the UnboundID LDAP SDK for Java (NEIL WILSON)
- Fix a SimpleBindRequest bug (Github)
- processSync in SimpleBindRequest allows empty password with set bindDN #40 (Github)
- UnboundID LDAP SDK for Java Hompepage (UnboundID)
- UnboundID LDAP SDK for Java release notes (Github)