VYPR
Unrated severityNVD Advisory· Published Feb 14, 2014· Updated Apr 29, 2026

CVE-2012-1100

CVE-2012-1100

Description

Red Hat JBoss Operations Network (JON) 3.0.x before 3.0.1, 2.4.2, and earlier, when LDAP authentication is enabled and the LDAP bind account credentials are invalid, allows remote attackers to login to LDAP-based accounts via an arbitrary password in a login request.

Affected products

9
  • cpe:2.3:a:redhat:jboss_operations_network:*:*:*:*:*:*:*:*+ 8 more
    • cpe:2.3:a:redhat:jboss_operations_network:*:*:*:*:*:*:*:*range: <=2.4.1
    • cpe:2.3:a:redhat:jboss_operations_network:2.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:jboss_operations_network:2.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:jboss_operations_network:2.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:jboss_operations_network:2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:jboss_operations_network:2.3:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:jboss_operations_network:2.3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:jboss_operations_network:2.4:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:jboss_operations_network:3.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.