Логотип exploitDog
bind:"BDU:2025-14421" OR bind:"CVE-2025-7493"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2025-14421" OR bind:"CVE-2025-7493"

Количество 13

Количество 13

fstec логотип

BDU:2025-14421

3 месяца назад

Уязвимость сервера FreeIpa, связанная с недостатками разграничения доступа, позволяющая нарушителю повысить свои привилегии

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2025-7493

2 месяца назад

A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability is similar to CVE-2025-4404, where it fails to validate the uniqueness of the krbCanonicalName. While the previously released version added validations for the admin@REALM credential, FreeIPA still does not validate the root@REALM canonical name, which can also be used as the realm administrator's name. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2025-7493

2 месяца назад

A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability is similar to CVE-2025-4404, where it fails to validate the uniqueness of the krbCanonicalName. While the previously released version added validations for the admin@REALM credential, FreeIPA still does not validate the root@REALM canonical name, which can also be used as the realm administrator's name. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2025-7493

2 месяца назад

A privilege escalation flaw from host to domain administrator was foun ...

CVSS3: 9.1
EPSS: Низкий
redos логотип

ROS-20251112-04

19 дней назад

Уязвимость 389-ds-base

CVSS3: 9.1
EPSS: Низкий
rocky логотип

RLSA-2025:20994

10 дней назад

Important: ipa security update

EPSS: Низкий
rocky логотип

RLSA-2025:17085

около 2 месяцев назад

Important: ipa security update

EPSS: Низкий
github логотип

GHSA-vm59-52f9-r52r

2 месяца назад

A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability is similar to CVE-2025-4404, where it fails to validate the uniqueness of the krbCanonicalName. While the previously released version added validations for the admin@REALM credential, FreeIPA still does not validate the root@REALM canonical name, which can also be used as the realm administrator's name. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.

CVSS3: 9.1
EPSS: Низкий
oracle-oval логотип

ELSA-2025-20928

6 дней назад

ELSA-2025-20928: ipa security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-17649

20 дней назад

ELSA-2025-17649: ipa security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-17129

2 месяца назад

ELSA-2025-17129: idm:DL1 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-17085

2 месяца назад

ELSA-2025-17085: ipa security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-17084

2 месяца назад

ELSA-2025-17084: ipa security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2025-14421

Уязвимость сервера FreeIpa, связанная с недостатками разграничения доступа, позволяющая нарушителю повысить свои привилегии

CVSS3: 9.1
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2025-7493

A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability is similar to CVE-2025-4404, where it fails to validate the uniqueness of the krbCanonicalName. While the previously released version added validations for the admin@REALM credential, FreeIPA still does not validate the root@REALM canonical name, which can also be used as the realm administrator's name. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.

CVSS3: 9.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2025-7493

A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability is similar to CVE-2025-4404, where it fails to validate the uniqueness of the krbCanonicalName. While the previously released version added validations for the admin@REALM credential, FreeIPA still does not validate the root@REALM canonical name, which can also be used as the realm administrator's name. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.

CVSS3: 9.1
0%
Низкий
2 месяца назад
debian логотип
CVE-2025-7493

A privilege escalation flaw from host to domain administrator was foun ...

CVSS3: 9.1
0%
Низкий
2 месяца назад
redos логотип
ROS-20251112-04

Уязвимость 389-ds-base

CVSS3: 9.1
0%
Низкий
19 дней назад
rocky логотип
RLSA-2025:20994

Important: ipa security update

0%
Низкий
10 дней назад
rocky логотип
RLSA-2025:17085

Important: ipa security update

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-vm59-52f9-r52r

A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability is similar to CVE-2025-4404, where it fails to validate the uniqueness of the krbCanonicalName. While the previously released version added validations for the admin@REALM credential, FreeIPA still does not validate the root@REALM canonical name, which can also be used as the realm administrator's name. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.

CVSS3: 9.1
0%
Низкий
2 месяца назад
oracle-oval логотип
ELSA-2025-20928

ELSA-2025-20928: ipa security update (IMPORTANT)

6 дней назад
oracle-oval логотип
ELSA-2025-17649

ELSA-2025-17649: ipa security update (IMPORTANT)

20 дней назад
oracle-oval логотип
ELSA-2025-17129

ELSA-2025-17129: idm:DL1 security update (IMPORTANT)

2 месяца назад
oracle-oval логотип
ELSA-2025-17085

ELSA-2025-17085: ipa security update (IMPORTANT)

2 месяца назад
oracle-oval логотип
ELSA-2025-17084

ELSA-2025-17084: ipa security update (IMPORTANT)

2 месяца назад

Уязвимостей на страницу