Back to Database
Status published
Critical
CVE-2017-10807
JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate...
Vulnerability Description
JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enabled.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-10807
Credits & Attribution
No credits recorded in the NVD database.
References
More from jabberd2
View All →CVE-2017-18226
The Gentoo net-im/jabberd2 package through 2.6.1 sets the ownership of...
Medium
5.5
CVE-2017-18225
The Gentoo net-im/jabberd2 package through 2.6.1 installs jabberd, jabberd2-c2s, jabberd2-router,...
High
7.8
CVE-2015-2058
c2s/c2s.c in Jabber Open Source Server 2.3.2 and earlier truncates...
Medium
6.5
CVE-2011-1755
jabberd2 before 2.2.14 does not properly detect recursion during entity...
High
7.5
Affected Vendor
jabberd2
View all reports →Affected Software
jabberd2
Vulnerable Versions:
0
Timeline
Official Publish:
July 4th, 2017
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.