CVE-2018-1000134 is a critical Incorrect Access Control vulnerability in the UnboundID LDAP SDK (pingidentity ldapsdk) affecting versions between commits 801111d8b5c732266a5dbd4b3bb0b6c7b94d7afb and 8471904a02438c03965d21367890276bc25fa5a6. This flaw allows an unauthenticated attacker to impersonate any valid user by providing a legitimate username with an empty password, bypassing authentication on vulnerable LDAP servers that do not perform additional validation. With a CVSS score of 9.8 (Critical), the vulnerability poses a significant risk of complete compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the potential impact remains high.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.1.0, <= 4.0.5CPE matchmatch criteria | cpe:2.3:a:pingidentity:ldapsdk:*:*:*:*:*:java:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.