Credentials management in Spring Security - CVE-2019-11272
Published: July 2, 2019 / Updated: July 2, 2019
Vulnerability identifier: #VU18957
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-11272
CWE-ID: CWE-255
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain unauthorized access to a system.
The vulnerability exist due to the PlaintextPasswordEncoder uses plain text passwords. A local user can bypass authentication process using a password of "null" and gain unauthorized access to the targeted system.
Affected software
Spring Security
Crucible Server
Crucible Data Center
Fuse
IBM Cognos Controller
Crucible Server
Crucible Data Center
Fuse
IBM Cognos Controller
How to mitigate CVE-2019-11272
Install updates from vendor's website.
Spring Security - update to 4.2.13
Crucible Server - update to 4.9.11
Crucible Data Center - update to 4.9.11
Fuse - update to 7.6.0
IBM Cognos Controller - addressed in versions 10.4.1.0.15, 10.4.2.0.2
Crucible Server - update to 4.9.11
Crucible Data Center - update to 4.9.11
Fuse - update to 7.6.0
IBM Cognos Controller - addressed in versions 10.4.1.0.15, 10.4.2.0.2