VYPR
Medium severity6.5NVD Advisory· Published Jan 18, 2018· Updated Jun 17, 2026

CVE-2017-12197

CVE-2017-12197

Description

It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a disabled account would be able to bypass security restrictions and possibly access sensitive information.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.kohsuke:libpam4jMaven
< 1.101.10

Affected products

7
  • cpe:2.3:a:libpam4j_project:libpam4j:*:*:*:*:*:*:*:*
    Range: <=1.8
  • Debian/linux3 versions
    cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
  • ghsa-coords
    Range: < 1.10
  • Red Hat, Inc./libpam4jv5
    Range: up to and including 1.8

Patches

Vulnerability mechanics

References

10

News mentions

0

No linked articles in our index yet.