PT-2019-14305 · Trend Micro · Deep Security Manager
Published
2019-10-17
·
Updated
2020-08-24
·
CVE-2019-15626
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Deep Security Manager versions 10.0 through 12.0
Description
The issue concerns the transmission of initial LDAP communication in clear text when the application is configured in a certain way. This may result in a confidentiality impact, but it does not affect integrity or availability.
Recommendations
For versions 10.0 through 12.0, consider reconfiguring the application to encrypt LDAP communication to mitigate the risk of confidentiality impact.
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Deep Security Manager