Improper Authentication in Go LDAP - CVE-2017-14623
Published: November 21, 2022
Vulnerability identifier: #VU69453
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-14623
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in processing authentication requests. A remote attacker can bypass authentication process and login with an empty password under certain conditions.
Affected software
Go LDAP
IBM CICS TX Standard
IBM CICS TX Advanced
IBM CICS TX Standard
IBM CICS TX Advanced
How to mitigate CVE-2017-14623
Install updates from vendor's website.
Go LDAP - update to 3.0.0
IBM CICS TX Standard - update to 11.1.0.0 ifix5
IBM CICS TX Advanced - update to 11.1.0.0 ifix5
IBM CICS TX Standard - update to 11.1.0.0 ifix5
IBM CICS TX Advanced - update to 11.1.0.0 ifix5