Vulnerability CVE-2012-2746


Published: 2012-07-03   Modified: 2012-07-04

Description:
389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), when the password of a LDAP user has been changed and audit logging is enabled, saves the new password to the log in plain text, which allows remote authenticated users to read the password.

Type:

CWE-310

(Cryptographic Issues)

CVSS2 => (AV:N/AC:H/Au:S/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
2.1/10
2.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Remote
High
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Redhat -> Directory server 
Fedoraproject -> 389 directory server 

 References:
https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03772083
https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03772083
https://fedorahosted.org/389/ticket/365
https://bugzilla.redhat.com/show_bug.cgi?id=833482
http://xforce.iss.net/xforce/xfdb/76595
http://www.securityfocus.com/bid/54153
http://www.osvdb.org/83329
http://secunia.com/advisories/49734
http://rhn.redhat.com/errata/RHSA-2012-1041.html
http://rhn.redhat.com/errata/RHSA-2012-0997.html
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:19241
http://directory.fedoraproject.org/wiki/Release_Notes

Copyright 2024, cxsecurity.com

 

Back to Top