Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-8105

Опубликовано: 05 мар. 2015
Источник: redhat
CVSS2: 5.8
EPSS Низкий

Описание

389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does not properly restrict access to the "cn=changelog" LDAP sub-tree, which allows remote attackers to obtain sensitive information from the changelog via unspecified vectors.

An information disclosure flaw was found in the way the 389 Directory Server stored information in the Changelog that is exposed via the 'cn=changelog' LDAP sub-tree. An unauthenticated user could in certain cases use this flaw to read data from the Changelog, which could include sensitive information such as plain-text passwords.

Дополнительная информация

Статус:

Important
Дефект:
CWE-862->CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1167858389-ds-base: information disclosure through 'cn=changelog' subtree

EPSS

Процентиль: 62%
0.00435
Низкий

5.8 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does not properly restrict access to the "cn=changelog" LDAP sub-tree, which allows remote attackers to obtain sensitive information from the changelog via unspecified vectors.

nvd
больше 10 лет назад

389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does not properly restrict access to the "cn=changelog" LDAP sub-tree, which allows remote attackers to obtain sensitive information from the changelog via unspecified vectors.

debian
больше 10 лет назад

389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does n ...

github
больше 3 лет назад

389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does not properly restrict access to the "cn=changelog" LDAP sub-tree, which allows remote attackers to obtain sensitive information from the changelog via unspecified vectors.

oracle-oval
больше 10 лет назад

ELSA-2015-0628: 389-ds-base security, bug fix, and enhancement update (IMPORTANT)

EPSS

Процентиль: 62%
0.00435
Низкий

5.8 Medium

CVSS2