Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux
CVE-2012-2678
CVE information
Published
Last Modified
CVSSv2.0 Severity
Impact Analysis
Description
389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), after the password for a LDAP user has been changed and before the server has been reset, allows remote attackers to read the plaintext password via the unhashed#user#password attribute..
CVSSv2.0 Score
- Severity
- Low
- Base Score
- 1.2/10
- Exploit Score
- 1.9/10
- Access Vector
- Local
- Access Complexity
- High
- Authentication Required
- None
- Impact Score
- 2.9/10
- Confidentiality Impact
- Partial
- Availability Impact
- None
- Integrity Impact
- None
Products Affected
CPE | Affected | Vulnerable | Excluding | Edit |
---|---|---|---|---|
cpe:2.3:a:redhat:directory_server:*:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:redhat:directory_server:8.1:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:redhat:directory_server:7.1:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:redhat:directory_server:8.0:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.5:rc4:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.3:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.5:rc1:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.8:rc2:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.8:rc1:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.9.9:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.8.3:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.6:rc3:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.6:a3:*:*:*: |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:*:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.6:rc1:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.8.2:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.7.5:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.1:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.2:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.5:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.8:alpha2:*: |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.10.1:*:*:*: |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.6:rc6:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.10:rc1:*:*: |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.8:alpha3:*: |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.6.1:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.5:rc3:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.6:a4:*:*:*: |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.10.3:*:*:*: |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.11.1:*:*:*: |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.10.4:*:*:*: |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.10.7:*:*:*: |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.5:rc2:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.10.2:*:*:*: |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.8:alpha1:*: |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.6:rc2:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.6:a2:*:*:*: |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.6:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.6:rc7:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.8.1:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.10:alpha8:* |
Yes
|
- | - | |
cpe:2.3:a:fedoraproject:389_directory_server:1.2.7:alpha3:*: |
Yes
|
- | - |
References
- http://www.securityfocus.com/bid/54153
- http://directory.fedoraproject.org/wiki/Release_Notes
- http://osvdb.org/83336
- http://rhn.redhat.com/errata/RHSA-2012-1041.html
- http://secunia.com/advisories/49734
- http://rhn.redhat.com/errata/RHSA-2012-0997.html
- https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03772083
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1