Apache Karaf uses the LDAPLoginModule to authenticate users to a directory via LDAP. It does not, however, encode usernames properly and hence is vulnerable to LDAP injection attacks. While it appears that it is not possible to exploit this vulnerability to allow an attacker to gain remote access, it does allow an attacker to insert special characters into the search query step. Therefore, it can potentially be exploited as part of a Denial of Service attack.
Find out more about CVE-2016-8750 from the MITRE CVE dictionary dictionary and NIST NVD.
CVSS3 Base Score | 7.5 |
---|---|
CVSS3 Base Metrics | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Attack Vector | Network |
Attack Complexity | Low |
Privileges Required | None |
User Interaction | None |
Scope | Unchanged |
Confidentiality | None |
Integrity Impact | None |
Availability Impact | High |
Platform | Errata | Release Date |
---|---|---|
Red Hat JBoss Fuse 6.3 | RHSA-2018:1322 | 2018-05-03 |
Red Hat JBoss A-MQ 6.3 | RHSA-2018:1322 | 2018-05-03 |
Platform | Package | State |
---|---|---|
Red Hat OpenStack Platform 9.0 | opendaylight | Will not fix |
Red Hat OpenStack Platform 8.0 (Liberty) | opendaylight | Will not fix |
Red Hat OpenStack Platform 13.0 (Queens) | opendaylight | Will not fix |
Red Hat OpenStack Platform 12.0 | opendaylight | Will not fix |
Red Hat OpenStack Platform 11.0 (Ocata) | opendaylight | Will not fix |
Red Hat OpenStack Platform 10 | opendaylight | Will not fix |