The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty password.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
vmware spring security 3.1.1 |
||
vmware spring security 3.1.2 |
||
vmware spring security 3.1.3 |
||
vmware spring security 3.2.0 |
||
vmware spring security 3.1.4 |
||
vmware spring security 3.1.5 |
||
vmware spring security 3.1.0 |
||
vmware spring security 3.2.1 |