Access Control Flaw in Neo4j Enterprise Database Server
CVE-2018-18389
9.8CRITICAL
What is CVE-2018-18389?
An access control vulnerability exists in Neo4j Enterprise Database Server versions 3.4.x prior to 3.4.9. Due to improper handling of user authentication and authorization, an attacker can exploit this flaw by utilizing valid usernames along with arbitrary passwords to gain unauthorized access to the database server. This issue may lead to significant security risks, including unauthorized data access and manipulation, highlighting the importance of timely updates and patches for database systems.
