PT-2019-14305 · Trend Micro · Deep Security Manager

Published

2019-10-17

·

Updated

2020-08-24

·

CVE-2019-15626

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Deep Security Manager versions 10.0 through 12.0
Description The issue concerns the transmission of initial LDAP communication in clear text when the application is configured in a certain way. This may result in a confidentiality impact, but it does not affect integrity or availability.
Recommendations For versions 10.0 through 12.0, consider reconfiguring the application to encrypt LDAP communication to mitigate the risk of confidentiality impact.

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-15626

Affected Products

Deep Security Manager