4
CVSSv2

CVE-2016-8750

Published: 19/02/2018 Updated: 26/04/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

Apache Karaf before 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not encoding usernames properly and hence was vulnerable to LDAP injection attacks leading to a denial of service.

Vulnerable Product Search on Vulmon Subscribe to Product

apache karaf

Vendor Advisories

Synopsis Moderate: Red Hat JBoss Fuse/A-MQ 63 R7 security and bug fix update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat JBoss Fuse and Red Hat JBoss A-MQRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerabilit ...
Apache Karaf uses the LDAPLoginModule to authenticate users to a directory via LDAP It does not, however, encode usernames properly and hence is vulnerable to LDAP injection attacks While it appears that it is not possible to exploit this vulnerability to allow an attacker to gain remote access, it does allow an attacker to insert special charact ...