Show filters
183 Total Results
Displaying 21-30 of 183
Sort by:
Attacker Value
Unknown
CVE-2019-4547
Disclosure Date: October 28, 2020 (last updated February 22, 2025)
IBM Security Directory Server 6.4.0 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 165949.
0
Attacker Value
Unknown
CVE-2019-4563
Disclosure Date: October 28, 2020 (last updated February 22, 2025)
IBM Security Directory Server 6.4.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 166624.
0
Attacker Value
Unknown
CVE-2019-4551
Disclosure Date: February 03, 2020 (last updated February 21, 2025)
IBM Security Directory Server 6.4.0 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 165953.
0
Attacker Value
Unknown
CVE-2019-4548
Disclosure Date: February 03, 2020 (last updated February 21, 2025)
IBM Security Directory Server 6.4.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 165950.
0
Attacker Value
Unknown
CVE-2019-4562
Disclosure Date: February 03, 2020 (last updated February 21, 2025)
IBM Security Directory Server 6.4.0 stores sensitive information in URLs. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referer header or browser history. IBM X-Force ID: 166623.
0
Attacker Value
Unknown
CVE-2019-4541
Disclosure Date: February 03, 2020 (last updated November 27, 2024)
IBM Security Directory Server 6.4.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 165814.
0
Attacker Value
Unknown
CVE-2019-4540
Disclosure Date: February 03, 2020 (last updated February 21, 2025)
IBM Security Directory Server 6.4.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 165813.
0
Attacker Value
Unknown
CVE-2019-4550
Disclosure Date: February 03, 2020 (last updated November 27, 2024)
IBM Security Directory Server 6.4.0 is deployed with active debugging code that can create unintended entry points. IBM X-Force ID: 165952.
0
Attacker Value
Unknown
CVE-2010-3282
Disclosure Date: January 09, 2020 (last updated February 21, 2025)
389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw) in cleartext when changing cn=config:nsslapd-rootpw, which might allow local users to obtain sensitive information by reading the log.
0
Attacker Value
Unknown
CVE-2019-14907
Disclosure Date: December 10, 2019 (last updated February 21, 2025)
All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or above) then the string obtained from the client, after a failed character conversion, is printed. Such strings can be provided during the NTLMSSP authentication exchange. In the Samba AD DC in particular, this may cause a long-lived process(such as the RPC server) to terminate. (In the file server case, the most likely target, smbd, operates as process-per-client and so a crash there is harmless).
0