Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-4992

Опубликовано: 17 июн. 2016
Источник: redhat
CVSS3: 4.3
CVSS2: 3.5
EPSS Низкий

Описание

389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to infer the existence of RDN component objects.

An information disclosure flaw was found in 389 Directory Server. A user with no access to objects in certain LDAP sub-tree could send LDAP ADD operations with a specific object name. The error message returned to the user was different based on whether the target object existed or not.

Дополнительная информация

Статус:

Low
Дефект:
CWE-209
https://bugzilla.redhat.com/show_bug.cgi?id=1347760389-ds-base: Information disclosure via repeated use of LDAP ADD operation

EPSS

Процентиль: 55%
0.00331
Низкий

4.3 Medium

CVSS3

3.5 Low

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to infer the existence of RDN component objects.

CVSS3: 7.5
nvd
больше 8 лет назад

389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to infer the existence of RDN component objects.

CVSS3: 7.5
debian
больше 8 лет назад

389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, ...

CVSS3: 7.5
github
больше 3 лет назад

389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to infer the existence of RDN component objects.

oracle-oval
почти 9 лет назад

ELSA-2016-2765: 389-ds-base security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 55%
0.00331
Низкий

4.3 Medium

CVSS3

3.5 Low

CVSS2

Уязвимость CVE-2016-4992