PT-2015-6108 · Red Hat · 389 Directory Server

Cviecco

·

Publicado

2015-10-15

·

Atualizado

2024-06-15

·

CVE-2015-3230

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions 389 Directory Server versions prior to 1.3.3.12
Description The issue allows remote attackers to have an unspecified impact by requesting to use a disabled cipher, as the nsSSL3Ciphers preference is not enforced when creating an sslSocket.
Recommendations For versions prior to 1.3.3.12, update to version 1.3.3.12 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-3230
MGASA-2015-0402
OPENSUSE-SU-2024:10157-1

Produtos afetados

389 Directory Server