ZeroHour

CVE-2018-18389

PoC
CVSS 3.0
9.8 critical
EPSS
2%p79
Published
()
Modified
Description

Due to incorrect access control in Neo4j Enterprise Database Server 3.4.x before 3.4.9, the setting of LDAP for authentication with STARTTLS, and System Account for authorization, allows an attacker to log into the server by sending any valid username with an arbitrary password.

Vendors
neo4j
Products
neo4j
Weakness
CWE-287
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.