CVE-2011-1561

IBM AIX 6.1 - Unauthenticated Authentication Bypass via LDAP Login

Title source: llm
STIX 2.1

Description

The LDAP login feature in bos.rte.security 6.1.6.4 in IBM AIX 6.1, when ldap_auth is enabled in ldap.cfg, allows remote attackers to bypass authentication via a login attempt with an arbitrary password.

References (5)

Core 5
Core References
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=isg1IZ97416
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1025273
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0836
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43968

Scores

EPSS 0.0205
EPSS Percentile 78.9%

Details

CWE
CWE-287
Status published
Products (1)
ibm/aix 6.1
Published Apr 05, 2011
Tracked Since Feb 18, 2026