The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability. This vulnerability allows the application to accept manual entry of any active directory (AD) account provisioned in the application without supplying a password, resulting in access to the application as the supplied AD account, with all associated privileges.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2021-12-15T18:05:16.799122Z

Updated: 2024-09-16T23:11:47.219Z

Reserved: 2021-11-16T00:00:00

Link: CVE-2021-43935

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-12-15T19:15:15.873

Modified: 2024-11-21T06:30:01.987

Link: CVE-2021-43935

cve-icon Redhat

No data.