Improper Authentication in Go LDAP - CVE-2017-14623

 

Improper Authentication in Go LDAP - CVE-2017-14623

Published: November 21, 2022


Vulnerability identifier: #VU69453
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-14623
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in processing authentication requests. A remote attacker can bypass authentication process and login with an empty password under certain conditions.


Affected software

Go LDAP
IBM CICS TX Standard
IBM CICS TX Advanced

How to mitigate CVE-2017-14623

Install updates from vendor's website.

Go LDAP - update to 3.0.0
IBM CICS TX Standard - update to 11.1.0.0 ifix5
IBM CICS TX Advanced - update to 11.1.0.0 ifix5

External References

Related Security Bulletins