Weak password requirements in UnboundID LDAP SDK for Java - CVE-2018-1000134
Published: February 9, 2023
Vulnerability identifier: #VU72082
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1000134
CWE-ID: CWE-521
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows an attacker to compromise the affected application.
The vulnerability exists due to the application does not check for empty passwords when running in synchronous mode. A remote attacker can provide a valid username with an empty password and gain unauthorized access to the application.
Affected software
UnboundID LDAP SDK for Java
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
IBM Business Automation Manager Open Editions
Fedora
unboundid-ldapsdk
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
IBM Business Automation Manager Open Editions
Fedora
unboundid-ldapsdk
How to mitigate CVE-2018-1000134
Install updates from vendor's website.
UnboundID LDAP SDK for Java - update to 4.0.5
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.2
IBM Business Automation Manager Open Editions - update to 8.0.2
unboundid-ldapsdk - addressed in versions 4.0.5-1.fc26, 4.0.5-1.fc27, 4.0.5-1.fc28
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.2
IBM Business Automation Manager Open Editions - update to 8.0.2
unboundid-ldapsdk - addressed in versions 4.0.5-1.fc26, 4.0.5-1.fc27, 4.0.5-1.fc28
External References
Related Security Bulletins
- Weak password policy in UnboundID LDAP SDK
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- Multiple vulnerabilities in Red Hat Process Automation Manager 7.13
- Fedora 28 update for unboundid-ldapsdk
- Fedora 27 update for unboundid-ldapsdk
- Fedora 26 update for unboundid-ldapsdk