Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-1849

Опубликовано: 23 мар. 2015
Источник: redhat
CVSS2: 1.7
EPSS Низкий

Описание

AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows attackers to obtain sensitive information via vectors involving logging the LDAP bind credential password when TRACE logging is enabled.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Data Grid 6jboss-negotiation-extrasAffected
Red Hat JBoss Data Virtualization 6jboss-negotiation-extrasAffected
Red Hat JBoss Fuse Service Works 6jboss-negotiation-extrasAffected
Red Hat JBoss Operations Network 3jboss-negotiation-extrasAffected
Red Hat JBoss Portal 6jboss-negotiation-extrasAffected
Red Hat JBoss Enterprise Application Platform 6.4FixedRHEA-2015:107704.06.2015
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5jboss-as-appclientFixedRHEA-2015:107604.06.2015
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5jbossas-appclientFixedRHEA-2015:107604.06.2015
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5jbossas-bundlesFixedRHEA-2015:107604.06.2015
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5jboss-as-cliFixedRHEA-2015:107604.06.2015

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=1208580EAP: LDAP bind password is being logged with TRACE log level

EPSS

Процентиль: 53%
0.00303
Низкий

1.7 Low

CVSS2

Связанные уязвимости

CVSS3: 5.9
nvd
больше 8 лет назад

AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows attackers to obtain sensitive information via vectors involving logging the LDAP bind credential password when TRACE logging is enabled.

CVSS3: 5.9
github
больше 3 лет назад

AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows attackers to obtain sensitive information via vectors involving logging the LDAP bind credential password when TRACE logging is enabled.

EPSS

Процентиль: 53%
0.00303
Низкий

1.7 Low

CVSS2