7.5
CVSSv2

CVE-2015-1169

Published: 10/02/2015 Updated: 11/02/2015
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Apereo Central Authentication Service (CAS) Server prior to 3.5.3 allows remote malicious users to conduct LDAP injection attacks via a crafted username, as demonstrated by using a wildcard and a valid password to bypass LDAP authentication.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apereo central authentication service

Exploits

CAS Server version 352 allows remote attackers to bypass LDAP authentication via crafted wildcards ...