5
CVSSv2

CVE-2014-3562

Published: 21/08/2014 Updated: 13/02/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote malicious users to obtain sensitive replicated metadata by searching the directory.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fedoraproject 389 directory server 1.3.0.3

fedoraproject 389 directory server 1.2.5

fedoraproject 389 directory server 1.2.3

fedoraproject 389 directory server 1.2.11.9

fedoraproject 389 directory server 1.3.0.7

fedoraproject 389 directory server 1.3.0.5

fedoraproject 389 directory server 1.2.8

fedoraproject 389 directory server 1.2.11.23

redhat enterprise linux 7.0

redhat enterprise linux 6.0

fedoraproject 389 directory server 1.2.9.9

fedoraproject 389 directory server 1.2.11.8

fedoraproject 389 directory server 1.2.8.3

fedoraproject 389 directory server 1.2.6

fedoraproject 389 directory server 1.2.10

fedoraproject 389 directory server 1.2.11.13

fedoraproject 389 directory server 1.2.8.2

fedoraproject 389 directory server 1.2.11.22

fedoraproject 389 directory server 1.3.0.8

fedoraproject 389 directory server 1.2.11.21

fedoraproject 389 directory server 1.3.0.4

fedoraproject 389 directory server 1.2.7.5

fedoraproject 389 directory server 1.2.1

fedoraproject 389 directory server 1.2.11.25

fedoraproject 389 directory server 1.2.11.20

fedoraproject 389 directory server 1.2.11.26

fedoraproject 389 directory server 1.2.2

fedoraproject 389 directory server 1.2.11.17

fedoraproject 389 directory server 1.3.0.2

fedoraproject 389 directory server 1.2.11.19

fedoraproject 389 directory server 1.2.11.12

fedoraproject 389 directory server 1.2.6.1

redhat directory server 8.0

fedoraproject 389 directory server 1.2.11.6

fedoraproject 389 directory server 1.2.11.10

fedoraproject 389 directory server 1.2.11.11

fedoraproject 389 directory server 1.2.10.3

fedoraproject 389 directory server 1.2.11.1

fedoraproject 389 directory server 1.2.11.5

fedoraproject 389 directory server 1.2.10.4

fedoraproject 389 directory server 1.2.10.11

fedoraproject 389 directory server 1.2.10.2

fedoraproject 389 directory server 1.2.11.14

fedoraproject 389 directory server 1.3.0.6

fedoraproject 389 directory server 1.2.8.1

fedoraproject 389 directory server 1.2.11.15

fedoraproject 389 directory server 1.2.7

Vendor Advisories

Debian Bug report logs - #757437 389-ds-base: CVE-2014-3562: unauthenticated information disclosure Package: src:389-ds-base; Maintainer for src:389-ds-base is Debian FreeIPA Team <pkg-freeipa-devel@alioth-listsdebiannet>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 8 Aug 2014 06:39:01 UTC Sev ...
It was found that when replication was enabled for each attribute in 389 Directory Server, which is the default configuration, the server returned replicated metadata when the directory was searched while debugging was enabled A remote attacker could use this flaw to disclose potentially sensitive information ...