PT-2017-6529 · Red Hat+1 · 389 Directory Server+2
Simo Sorce
·
Publicado
2015-04-28
·
Atualizado
2024-06-15
·
CVE-2015-1854
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
389 Directory Server versions prior to 1.3.3.10
Description
The issue allows attackers to bypass intended access restrictions and modify directory entries. This is achieved through a crafted ldapmodrdn call.
Recommendations
For versions prior to 1.3.3.10, update to version 1.3.3.10 or later to resolve the issue. As a temporary workaround, consider restricting access to the ldapmodrdn functionality until a patch is applied.
Correção
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
389 Directory Server
Centos
Red Hat