Show filters
183 Total Results
Displaying 11-20 of 183
Sort by:
Attacker Value
Unknown

CVE-2022-33161

Disclosure Date: October 14, 2023 (last updated October 19, 2023)
IBM Security Directory Server 6.4.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. X-Force ID: 228569.
Attacker Value
Unknown

CVE-2022-32755

Disclosure Date: October 14, 2023 (last updated October 19, 2023)
IBM Security Directory Server 6.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 228505.
Attacker Value
Unknown

CVE-2022-33164

Disclosure Date: September 08, 2023 (last updated October 08, 2023)
IBM Security Directory Server 7.2.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view or write to arbitrary files on the system. IBM X-Force ID: 228579.
Attacker Value
Unknown

CVE-2022-31244

Disclosure Date: April 25, 2023 (last updated October 08, 2023)
Nokia OneNDS 17r2 has Insecure Permissions vulnerability that allows for privilege escalation.
Attacker Value
Unknown

CVE-2023-1055

Disclosure Date: February 27, 2023 (last updated October 08, 2023)
A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attribute which could lead into sensitive information leaked. An attacker with a local account where the cockpit-389-ds is running can list the processes and display the hashed passwords. The highest threat from this vulnerability is to data confidentiality.
Attacker Value
Unknown

CVE-2022-2850

Disclosure Date: October 14, 2022 (last updated October 08, 2023)
A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. This CVE is assigned against an incomplete fix of CVE-2021-3514.
Attacker Value
Unknown

CVE-2022-1949

Disclosure Date: June 02, 2022 (last updated December 18, 2024)
An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass. This may allow any remote unauthenticated user to issue a filter that allows searching for database items they do not have access to, including but not limited to potentially userPassword hashes and other sensitive data.
Attacker Value
Unknown

CVE-2022-0996

Disclosure Date: March 23, 2022 (last updated October 07, 2023)
A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication.
Attacker Value
Unknown

CVE-2021-3514

Disclosure Date: May 28, 2021 (last updated November 28, 2024)
When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash.
Attacker Value
Unknown

CVE-2020-35518

Disclosure Date: March 26, 2021 (last updated November 28, 2024)
When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.