VulnerabilityModified
CVE-2010-1596
Support Incident Tracker before 3.51, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.
MEDIUM 6.8EPSS 1.54%
Does this matter?
Lower severity and a low EPSS score (1.54%). Track it; it rarely justifies an emergency change on its own.
Description
Support Incident Tracker before 3.51, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.54% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- sitracker/support incident tracker
- Source
- cve@mitre.org
References
- http://bugs.sitracker.org/view.php?id=1047
- http://osvdb.org/61945
- http://secunia.com/advisories/38329Vendor Advisory
- http://sitracker.org/forum/viewtopic.php?f=4&t=1416979&p=2292
- http://sitracker.org/wiki/ReleaseNotes351Patch
- http://www.securityfocus.com/bid/37949
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55871
- http://bugs.sitracker.org/view.php?id=1047
- http://osvdb.org/61945
- http://secunia.com/advisories/38329Vendor Advisory
- http://sitracker.org/forum/viewtopic.php?f=4&t=1416979&p=2292
- http://sitracker.org/wiki/ReleaseNotes351Patch
- http://www.securityfocus.com/bid/37949
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55871
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.