CVE-2014-0097

All FrameworksSpring FrameworkCWE-OtherCVE-2014-0097

CVE-2014-0097

State: PUBLISHED · Published: 2017-05-25 · Updated: 2024-08-06 · Assigner: dell
Description
The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty password.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2014/0xxx/CVE-2014-0097.json