Описание
On 2.1.15 version and below of Lider module in LiderAhenk software is leaking it's configurations via an unsecured API. An attacker with an access to the configurations API could get valid LDAP credentials.
Ссылки
- ExploitThird Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.1.15 (включая)
cpe:2.3:a:pardus:liderahenk:*:*:*:*:*:*:*:*
EPSS
Процентиль: 60%
0.00405
Низкий
9.6 Critical
CVSS3
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-306
CWE-306
Связанные уязвимости
CVSS3: 9.6
github
больше 3 лет назад
On 2.1.15 version and below of Lider module in LiderAhenk software is leaking it's configurations via an unsecured API. An attacker with an access to the configurations API could get valid LDAP credentials.
EPSS
Процентиль: 60%
0.00405
Низкий
9.6 Critical
CVSS3
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-306
CWE-306