The Red Hat Directory Server before 8.2.11-13 and 389 Directory Server do not properly restrict access to entity attributes, which allows remote authenticated users to obtain sensitive information via a search query for the attribute.
CVSS Details
- CVSS 3.1 Base Score: 4.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade 389-ds-base-develUpgrade 389-ds-base-libsUpgrade 389-ds-base | Dec 1, 2016 | Jul 31, 2013 |
| Debian | — | Upgrade 389-ds-base | Jul 30, 2024 | Jul 31, 2013 |
| Oracle_linux | — | Upgrade 389-ds-base-develUpgrade 389-ds-base-libsUpgrade 389-ds-base | Oct 16, 2024 | Jul 31, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub