Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2011-1025

Опубликовано: 20 мар. 2011
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:openldap:openldap:2.4.6:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.7:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.8:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.9:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.10:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.11:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.12:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.13:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.14:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.15:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.16:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.17:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.18:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.19:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.20:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.21:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.22:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.23:*:*:*:*:*:*:*

EPSS

Процентиль: 91%
0.0728
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-287

Связанные уязвимости

ubuntu
больше 14 лет назад

bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.

redhat
почти 15 лет назад

bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.

debian
больше 14 лет назад

bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require ...

github
около 3 лет назад

bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.

oracle-oval
больше 14 лет назад

ELSA-2011-0347: openldap security update (MODERATE)

EPSS

Процентиль: 91%
0.0728
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-287