Логотип exploitDog
bind:CVE-2019-13057
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-13057

Количество 12

Количество 12

ubuntu логотип

CVE-2019-13057

больше 6 лет назад

An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)

CVSS3: 4.9
EPSS: Низкий
redhat логотип

CVE-2019-13057

больше 6 лет назад

An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2019-13057

больше 6 лет назад

An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)

CVSS3: 4.9
EPSS: Низкий
debian логотип

CVE-2019-13057

больше 6 лет назад

An issue was discovered in the server in OpenLDAP before 2.4.48. When ...

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-5x95-66xj-7chm

больше 3 лет назад

An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)

CVSS3: 4.9
EPSS: Низкий
fstec логотип

BDU:2019-04729

больше 6 лет назад

Уязвимость демона slapd пакета OpenLDAP, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:14353-1

почти 6 лет назад

Security update for openldap2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:2390-1

больше 6 лет назад

Security update for openldap2

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:2176-1

больше 6 лет назад

Security update for openldap2

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:2157-1

больше 6 лет назад

Security update for openldap2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:1210-1

почти 6 лет назад

Security update for openldap2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:2395-1

больше 6 лет назад

Security update for openldap2

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2019-13057

An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)

CVSS3: 4.9
1%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-13057

An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)

CVSS3: 6.5
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-13057

An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)

CVSS3: 4.9
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-13057

An issue was discovered in the server in OpenLDAP before 2.4.48. When ...

CVSS3: 4.9
1%
Низкий
больше 6 лет назад
github логотип
GHSA-5x95-66xj-7chm

An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)

CVSS3: 4.9
1%
Низкий
больше 3 лет назад
fstec логотип
BDU:2019-04729

Уязвимость демона slapd пакета OpenLDAP, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 6.5
1%
Низкий
больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2020:14353-1

Security update for openldap2

почти 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:2390-1

Security update for openldap2

больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:2176-1

Security update for openldap2

больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:2157-1

Security update for openldap2

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2020:1210-1

Security update for openldap2

почти 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:2395-1

Security update for openldap2

больше 6 лет назад

Уязвимостей на страницу