CyberRota Analysis
AI-GeneratedA vulnerability exists in the EAP's IIOP listener, which improperly accepts bind operations without authentication, enabling attackers to hijack JNDI lookups and redirect them to a malicious Object Request Broker (ORB). This flaw can lead to man-in-the-middle (MITM) attacks or denial-of-service (DoS) conditions on subsequent invocations. Organizations utilizing EAP should prioritize addressing this issue to safeguard their systems against potential exploitation.
Original NVD Description
A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a malicious ORB, achieving MITM or DoS on further invocations.