Описание
389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does not properly restrict access to the "cn=changelog" LDAP sub-tree, which allows remote attackers to obtain sensitive information from the changelog via unspecified vectors.
Релиз | Статус | Примечание |
---|---|---|
artful | not-affected | |
bionic | not-affected | |
cosmic | not-affected | |
devel | not-affected | |
disco | not-affected | |
esm-apps/bionic | not-affected | |
esm-apps/xenial | not-affected | |
esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was needed] |
lucid | DNE | |
precise | ignored | end of life |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
artful | not-affected | |
bionic | not-affected | |
cosmic | not-affected | |
devel | not-affected | |
disco | not-affected | |
esm-apps/bionic | not-affected | |
esm-apps/xenial | not-affected | |
esm-infra-legacy/trusty | not-affected | |
lucid | DNE | |
precise | not-affected |
Показывать по
Ссылки на источники
EPSS
5 Medium
CVSS2
Связанные уязвимости
389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does not properly restrict access to the "cn=changelog" LDAP sub-tree, which allows remote attackers to obtain sensitive information from the changelog via unspecified vectors.
389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does not properly restrict access to the "cn=changelog" LDAP sub-tree, which allows remote attackers to obtain sensitive information from the changelog via unspecified vectors.
389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does n ...
389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does not properly restrict access to the "cn=changelog" LDAP sub-tree, which allows remote attackers to obtain sensitive information from the changelog via unspecified vectors.
ELSA-2015-0628: 389-ds-base security, bug fix, and enhancement update (IMPORTANT)
EPSS
5 Medium
CVSS2