Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Oschlueter

#27562of 56,326
9.8Total CVSS
Vulnerabilities · 1
PT-2018-14432
9.8
2018-10-16
Neo4J · Neo4J Enterprise Database Server · CVE-2018-18389
**Name of the Vulnerable Software and Affected Versions** Neo4j Enterprise Database Server versions 3.4.x through 3.4.8 **Description** The issue arises from incorrect access control, allowing an attacker to log into the server by sending any valid username with an arbitrary password when LDAP is set for authentication with STARTTLS and System Account is used for authorization. **Recommendations** For Neo4j Enterprise Database Server versions 3.4.x through 3.4.8, update to version 3.4.9 or later to resolve the issue.