Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-15135

Опубликовано: 24 янв. 2018
Источник: nvd
CVSS3: 8.1
CVSS2: 4.3
EPSS Низкий

Описание

It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison operations correctly during the authentication process. A remote, unauthenticated attacker could potentially use this flaw to bypass the authentication process under very rare and specific circumstances.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:fedoraproject:389_directory_server:*:*:*:*:*:*:*:*
Версия от 1.3.6.1 (включая) до 1.4.0.3 (включая)

EPSS

Процентиль: 86%
0.02785
Низкий

8.1 High

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-287
CWE-287

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 8 лет назад

It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison operations correctly during the authentication process. A remote, unauthenticated attacker could potentially use this flaw to bypass the authentication process under very rare and specific circumstances.

CVSS3: 4.6
redhat
почти 8 лет назад

It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison operations correctly during the authentication process. A remote, unauthenticated attacker could potentially use this flaw to bypass the authentication process under very rare and specific circumstances.

CVSS3: 8.1
debian
почти 8 лет назад

It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0. ...

CVSS3: 8.1
github
больше 3 лет назад

It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison operations correctly during the authentication process. A remote, unauthenticated attacker could potentially use this flaw to bypass the authentication process under very rare and specific circumstances.

CVSS3: 5.9
fstec
почти 8 лет назад

Уязвимость службы каталогов уровня предприятия 389 Directory Server, связанная с неправильной аутентификацией, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 86%
0.02785
Низкий

8.1 High

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-287
CWE-287