It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users are recommended to upgrade to version 2.1.2, which fixes this issue.
| Vendor | Product | Versions |
|---|---|---|
| apache | kerby | 0 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| ibm | infosphere information | cert_advisory | 90% |
Updated severity to CRITICAL, added affected version 2.1.1, and marked the vulnerability as actively exploited.
Initial creation