Rapid7 Vulnerability & Exploit Database

Red Hat JBoss: CVE-2015-1849: LDAP bind password is being logged with TRACE log level

Free InsightVM Trial No Credit Card Necessary
Watch Demo See how it all works
Back to Search

Red Hat JBoss: CVE-2015-1849: LDAP bind password is being logged with TRACE log level

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
Published
09/19/2017
Created
07/25/2018
Added
02/08/2018
Modified
02/12/2018

Description

AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows attackers to obtain sensitive information via vectors involving logging the LDAP bind credential password when TRACE logging is enabled.

Solution(s)

  • jboss_enterprise_application_platform-cve-2015-1849-1

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;