Support Incident Tracker before 3.51, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/37949 | vdb entry |
http://sitracker.org/wiki/ReleaseNotes351 | patch |
http://sitracker.org/forum/viewtopic.php?f=4&t=1416979&p=2292 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/55871 | vdb entry |
http://osvdb.org/61945 | vdb entry |
http://secunia.com/advisories/38329 | third party advisory vendor advisory |
http://bugs.sitracker.org/view.php?id=1047 |