CVE-2012-2678

389 Directory Server <1.2.11.6 - Info Disclosure

Title source: llm
STIX 2.1

Description

389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), after the password for a LDAP user has been changed and before the server has been reset, allows remote attackers to read the plaintext password via the unhashed#user#password attribute.

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19353
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/49734
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/83336
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/54153
Third Party Advisory x_refsource_confirm
http://directory.fedoraproject.org/wiki/Release_Notes
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2012-1041.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2012-0997.html

Scores

EPSS 0.0064
EPSS Percentile 46.7%

Details

CWE
CWE-310
Status published
Products (25)
fedoraproject/389_directory_server 1.2.1
fedoraproject/389_directory_server 1.2.2
fedoraproject/389_directory_server 1.2.3
fedoraproject/389_directory_server 1.2.5 (5 CPE variants)
fedoraproject/389_directory_server 1.2.6 (9 CPE variants)
fedoraproject/389_directory_server 1.2.6.1
fedoraproject/389_directory_server 1.2.7 alpha3
fedoraproject/389_directory_server 1.2.7.5
fedoraproject/389_directory_server 1.2.8 alpha1 (5 CPE variants)
fedoraproject/389_directory_server 1.2.8.1
... and 15 more
Published Jul 03, 2012
Tracked Since Feb 18, 2026