MEDIUM · 6.8

CVE-2007-6714

DBMail before 2.2.9, when using authldap with an LDAP server that supports anonymous login such as Active Directory, allows remote attackers to bypass authentication via an empty password, which cause...

Vulnerability Description

DBMail before 2.2.9, when using authldap with an LDAP server that supports anonymous login such as Active Directory, allows remote attackers to bypass authentication via an empty password, which causes the LDAP bind to indicate success based on anonymous authentication.

CVSS Score

6.8

MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
DbmailDbmail2.2.6

Related Weaknesses (CWE)

References

FAQ

What is CVE-2007-6714?

CVE-2007-6714 is a vulnerability with a CVSS score of 6.8 (MEDIUM). DBMail before 2.2.9, when using authldap with an LDAP server that supports anonymous login such as Active Directory, allows remote attackers to bypass authentication via an empty password, which cause...

How severe is CVE-2007-6714?

CVE-2007-6714 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-6714?

Check the references section above for vendor advisories and patch information. Affected products include: Dbmail Dbmail.