Medium severity6.5NVD Advisory· Published Jan 18, 2018· Updated Jun 17, 2026
CVE-2017-12197
CVE-2017-12197
Description
It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a disabled account would be able to bypass security restrictions and possibly access sensitive information.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.kohsuke:libpam4jMaven | < 1.10 | 1.10 |
Affected products
7- cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
- Red Hat, Inc./libpam4jv5Range: up to and including 1.8
Patches
Vulnerability mechanics
References
10- access.redhat.com/errata/RHSA-2017:2904nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2017:2905nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2017:2906nvdThird Party AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-x9rg-q5fx-fx66ghsaADVISORY
- lists.debian.org/debian-lts-announce/2017/11/msg00008.htmlnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2017-12197ghsaADVISORY
- www.debian.org/security/2017/dsa-4025nvdThird Party AdvisoryWEB
- github.com/kohsuke/libpam4j/commit/02ffdff218283629ba4a902e7fe2fd44646abc21ghsaWEB
- github.com/kohsuke/libpam4j/issues/18ghsaWEB
News mentions
0No linked articles in our index yet.