Critical severity9.8NVD Advisory· Published Oct 16, 2018· Updated Jun 17, 2026
CVE-2018-18389
CVE-2018-18389
Description
Due to incorrect access control in Neo4j Enterprise Database Server 3.4.x before 3.4.9, the setting of LDAP for authentication with STARTTLS, and System Account for authorization, allows an attacker to log into the server by sending any valid username with an arbitrary password.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.neo4j:neo4j-enterpriseMaven | >= 3.4.0, < 3.4.9 | 3.4.9 |
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/neo4j/neo4j/issues/12047nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-h5f5-rj4r-42f6ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-18389ghsaADVISORY
- github.com/neo4j/neo4j/commit/46de5d01ae2741ffe04c36270fc62c6d490f65c9ghsaWEB
News mentions
0No linked articles in our index yet.