7.5

CVE-2012-1123

The mci_check_login function in api/soap/mc_api.php in the SOAP API in MantisBT before 1.2.9 allows remote attackers to bypass authentication via a null password.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mantisbt ≫ Mantisbt Version <= 1.2.8
Mantisbt ≫ Mantisbt Version 0.18.0
Mantisbt ≫ Mantisbt Version 0.19.0
Mantisbt ≫ Mantisbt Version 0.19.0 Update a1
Mantisbt ≫ Mantisbt Version 0.19.0 Update a2
Mantisbt ≫ Mantisbt Version 0.19.0 Update rc1
Mantisbt ≫ Mantisbt Version 0.19.1
Mantisbt ≫ Mantisbt Version 0.19.2
Mantisbt ≫ Mantisbt Version 0.19.3
Mantisbt ≫ Mantisbt Version 0.19.4
Mantisbt ≫ Mantisbt Version 0.19.5
Mantisbt ≫ Mantisbt Version 1.0.0
Mantisbt ≫ Mantisbt Version 1.0.0 Update a1
Mantisbt ≫ Mantisbt Version 1.0.0 Update a2
Mantisbt ≫ Mantisbt Version 1.0.0 Update a3
Mantisbt ≫ Mantisbt Version 1.0.0 Update rc1
Mantisbt ≫ Mantisbt Version 1.0.0 Update rc2
Mantisbt ≫ Mantisbt Version 1.0.0 Update rc3
Mantisbt ≫ Mantisbt Version 1.0.0 Update rc4
Mantisbt ≫ Mantisbt Version 1.0.0 Update rc5
Mantisbt ≫ Mantisbt Version 1.0.1
Mantisbt ≫ Mantisbt Version 1.0.2
Mantisbt ≫ Mantisbt Version 1.0.3
Mantisbt ≫ Mantisbt Version 1.0.4
Mantisbt ≫ Mantisbt Version 1.0.5
Mantisbt ≫ Mantisbt Version 1.0.6
Mantisbt ≫ Mantisbt Version 1.0.7
Mantisbt ≫ Mantisbt Version 1.0.8
Mantisbt ≫ Mantisbt Version 1.0.9
Mantisbt ≫ Mantisbt Version 1.1.0
Mantisbt ≫ Mantisbt Version 1.1.0 Update a1
Mantisbt ≫ Mantisbt Version 1.1.0 Update a2
Mantisbt ≫ Mantisbt Version 1.1.0 Update a3
Mantisbt ≫ Mantisbt Version 1.1.0 Update a4
Mantisbt ≫ Mantisbt Version 1.1.0 Update rc1
Mantisbt ≫ Mantisbt Version 1.1.0 Update rc2
Mantisbt ≫ Mantisbt Version 1.1.0 Update rc3
Mantisbt ≫ Mantisbt Version 1.1.1
Mantisbt ≫ Mantisbt Version 1.1.2
Mantisbt ≫ Mantisbt Version 1.1.3
Mantisbt ≫ Mantisbt Version 1.1.4
Mantisbt ≫ Mantisbt Version 1.1.5
Mantisbt ≫ Mantisbt Version 1.1.6
Mantisbt ≫ Mantisbt Version 1.1.7
Mantisbt ≫ Mantisbt Version 1.1.8
Mantisbt ≫ Mantisbt Version 1.1.9
Mantisbt ≫ Mantisbt Version 1.2.0
Mantisbt ≫ Mantisbt Version 1.2.0 Update alpha1
Mantisbt ≫ Mantisbt Version 1.2.0 Update alpha2
Mantisbt ≫ Mantisbt Version 1.2.0 Update alpha3
Mantisbt ≫ Mantisbt Version 1.2.0 Update rc1
Mantisbt ≫ Mantisbt Version 1.2.0 Update rc2
Mantisbt ≫ Mantisbt Version 1.2.1
Mantisbt ≫ Mantisbt Version 1.2.2
Mantisbt ≫ Mantisbt Version 1.2.3
Mantisbt ≫ Mantisbt Version 1.2.4
Mantisbt ≫ Mantisbt Version 1.2.5
Mantisbt ≫ Mantisbt Version 1.2.6
Mantisbt ≫ Mantisbt Version 1.2.7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.73% 0.884
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

http://secunia.com/advisories/51199
http://security.gentoo.org/glsa/glsa-201211-01.xml
http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092926.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-November/093063.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-November/093064.html
http://secunia.com/advisories/48258
Vendor Advisory
http://secunia.com/advisories/49572
Vendor Advisory
http://www.debian.org/security/2012/dsa-2500
http://www.mantisbt.org/bugs/changelog_page.php?version_id=140
http://www.openwall.com/lists/oss-security/2012/03/06/9
http://www.securityfocus.com/bid/52313
http://www.mantisbt.org/bugs/view.php?id=13901
Patch
https://github.com/mantisbt/mantisbt/commit/f5106be52cf6aa72c521f388e4abb5f0de1f1d7f
Patch