CVE-2018-18389

CRITICAL

Neo4j Enterprise Database Server 3.4.0-3.4.8 - Improper Authentication via LDAP STARTTLS Bypass

Title source: llm
STIX 2.1

Description

Due to incorrect access control in Neo4j Enterprise Database Server 3.4.x before 3.4.9, the setting of LDAP for authentication with STARTTLS, and System Account for authorization, allows an attacker to log into the server by sending any valid username with an arbitrary password.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/neo4j/neo4j/issues/12047

Scores

CVSS v3 9.8
EPSS 0.0192
EPSS Percentile 77.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (2)
neo4j/neo4j 3.4.0 - 3.4.9
org.neo4j/neo4j-enterprise 3.4.0 - 3.4.9Maven
Published Oct 16, 2018
Tracked Since Feb 18, 2026