Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, doesn't verify properly the password in some system-user-dn scenarios. As a result, users (clients/members) can be authenticated even if they provide invalid passwords.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Hazelcast 授权问题漏洞
Vulnerability Description
Hazelcast(Hazelcast IMDG)是美国Hazelcast公司的一套可扩展的开源数据分发平台。该平台支持多种分布式数据结构,支持分布式缓存等功能。 Hazelcast IMDG Enterprise 存在安全漏洞,该漏洞源于LdapLoginModule authentication方法在某些系统用户dn场景中不能正确验证密码。攻击者可利用该漏洞提供无效的密码,对其进行身份验证。以下产品及版本受到影响:4.x系列4.0.3之前版本, Jet Enterprise 4.x系列4.2之前版本。
CVSS Information
N/A
Vulnerability Type
N/A