AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows attackers to obtain sensitive information via vectors involving logging the LDAP bind credential password when TRACE logging is enabled.
The MITRE CVE dictionary describes this issue as:
Find out more about CVE-2015-1849 from the MITRE CVE dictionary dictionary and NIST NVD.
Base Score | 1.7 |
---|---|
Base Metrics | AV:L/AC:L/Au:S/C:P/I:N/A:N |
Access Vector | Local |
Access Complexity | Low |
Authentication | Single |
Confidentiality Impact | Partial |
Integrity Impact | None |
Availability Impact | None |
Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).
Platform | Errata | Release Date |
---|---|---|
Red Hat JBoss Enterprise Application Platform 6.4 | RHEA-2015:1077 | 2015-06-04 |
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5 Server | RHEA-2015:1076 | 2015-06-04 |
Red Hat JBoss Enterprise Application Platform 6 for RHEL 6 Server | RHEA-2015:1075 | 2015-06-04 |
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 7 Server | RHEA-2015:1074 | 2015-06-04 |
Red Hat JBoss Enterprise Application Platform 6 for RHEL 6 Server (jboss-ec2-eap) | RHBA-2015:1073 | 2015-06-04 |
Platform | Package | State |
---|---|---|
Red Hat JBoss Portal Platform 6 | jboss-negotiation-extras | Will not fix |
Red Hat JBoss Operations Network 3 | jboss-negotiation-extras | Will not fix |
Red Hat JBoss Fuse Service Works 6 | jboss-negotiation-extras | Will not fix |
Red Hat JBoss Data Virtualization 6 | jboss-negotiation-extras | Will not fix |
Red Hat JBoss Data Grid 6 | jboss-negotiation-extras | Will not fix |