389 Directory Server before 1.3.3.10 allows attackers to bypass intended access restrictions and modify directory entries via a crafted ldapmodrdn call.
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade 389-ds-base-libsUpgrade 389-ds-baseUpgrade 389-ds-base-devel | Aug 17, 2018 | Apr 28, 2015 |
| Debian | — | Upgrade 389-ds-base | Feb 20, 2019 | Sep 19, 2017 |
| Oracle_linux | — | Upgrade 389-ds-base-develUpgrade 389-ds-baseUpgrade 389-ds-base-libs | Oct 16, 2024 | Sep 19, 2017 |
| Suse | — | Upgrade 389-ds-develUpgrade 389-dsUpgrade lib389Upgrade libsvrcore0 | Feb 4, 2022 | Jun 2, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub