9.8
CVSSv3

CVE-2017-10807

Published: 04/07/2017 Updated: 04/11/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

JabberD 2.x (aka jabberd2) prior to 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enabled.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jabberd2 jabberd2

Vendor Advisories

Debian Bug report logs - #867032 jabberd2: CVE-2017-10807: allows anyone to authenticate using SASL ANONYMOUS, even when the option is not enabled Package: jabberd2; Maintainer for jabberd2 is Debian XMPP Maintainers <pkg-xmpp-devel@listsaliothdebianorg>; Source for jabberd2 is src:jabberd2 (PTS, buildd, popcon) Reported ...
It was discovered that jabberd2, a Jabber instant messenger server, allowed anonymous SASL connections, even if disabled in the configuration For the stable distribution (stretch), this problem has been fixed in version 240-3+deb9u1 We recommend that you upgrade your jabberd2 packages ...
JabberD 2x (aka jabberd2) before 261 allows anyone to authenticate using SASL ANONYMOUS, even when the saslanonymous c2sxml option is not enabled ...