Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2017-8028
Description:In Pivotal Spring-LDAP versions 1.3.0 - 2.3.1, when connected to some LDAP servers, when no additional attributes are bound, and when using LDAP BindAuthenticator with org.springframework.ldap.core.support.Defa ultTlsDirContextAuthenticationStrategy as the authentication strategy, and setting userSearch, authentication is allowed with an arbitrary password when the username is correct. This occurs because some LDAP vendors require an explicit operation for the LDAP bind to take effect.
Test IDs: 1.3.6.1.4.1.25623.1.1.1.2.2017.1180   1.3.6.1.4.1.25623.1.0.704046   1.3.6.1.4.1.25623.1.1.10.2018.0235  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2017-8028
https://pivotal.io/security/cve-2017-8028
Debian Security Information: DSA-4046 (Google Search)
https://www.debian.org/security/2017/dsa-4046
https://www.oracle.com/security-alerts/cpujan2021.html
https://www.oracle.com/security-alerts/cpujan2021.html
https://lists.debian.org/debian-lts-announce/2017/11/msg00026.html
RedHat Security Advisories: RHSA-2018:0319
https://access.redhat.com/errata/RHSA-2018:0319




© 1998-2025 E-Soft Inc. All rights reserved.