7.5
CVSSv2

CVE-2014-0097

Published: 25/05/2017 Updated: 20/04/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 7.3 | Impact Score: 3.4 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty password.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vmware spring security 3.1.1

vmware spring security 3.1.2

vmware spring security 3.1.3

vmware spring security 3.2.0

vmware spring security 3.1.4

vmware spring security 3.1.5

vmware spring security 3.1.0

vmware spring security 3.2.1

Vendor Advisories

The ActiveDirectoryLdapAuthenticator in Spring Security 320 to 321 and 310 to 315 does not check the password length If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty password ...