Lucene search

K
cveRedhatCVE-2011-1024
HistoryMar 20, 2011 - 2:00 a.m.

CVE-2011-1024

2011-03-2002:00:03
CWE-264
redhat
web.nvd.nist.gov
43
cve-2011-1024
openldap
authentication
security vulnerability
nvd

CVSS2

4.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:S/C:P/I:P/A:P

AI Score

9

Confidence

High

EPSS

0.004

Percentile

74.0%

chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka authentication-failure forwarding) is used, allows remote authenticated users to bypass external-program authentication by sending an invalid password to a slave server.

Affected configurations

Nvd
Node
openldapopenldapMatch2.4.6
OR
openldapopenldapMatch2.4.7
OR
openldapopenldapMatch2.4.8
OR
openldapopenldapMatch2.4.9
OR
openldapopenldapMatch2.4.10
OR
openldapopenldapMatch2.4.11
OR
openldapopenldapMatch2.4.12
OR
openldapopenldapMatch2.4.13
OR
openldapopenldapMatch2.4.14
OR
openldapopenldapMatch2.4.15
OR
openldapopenldapMatch2.4.16
OR
openldapopenldapMatch2.4.17
OR
openldapopenldapMatch2.4.18
OR
openldapopenldapMatch2.4.19
OR
openldapopenldapMatch2.4.20
OR
openldapopenldapMatch2.4.21
OR
openldapopenldapMatch2.4.22
OR
openldapopenldapMatch2.4.23
VendorProductVersionCPE
openldapopenldap2.4.6cpe:2.3:a:openldap:openldap:2.4.6:*:*:*:*:*:*:*
openldapopenldap2.4.7cpe:2.3:a:openldap:openldap:2.4.7:*:*:*:*:*:*:*
openldapopenldap2.4.8cpe:2.3:a:openldap:openldap:2.4.8:*:*:*:*:*:*:*
openldapopenldap2.4.9cpe:2.3:a:openldap:openldap:2.4.9:*:*:*:*:*:*:*
openldapopenldap2.4.10cpe:2.3:a:openldap:openldap:2.4.10:*:*:*:*:*:*:*
openldapopenldap2.4.11cpe:2.3:a:openldap:openldap:2.4.11:*:*:*:*:*:*:*
openldapopenldap2.4.12cpe:2.3:a:openldap:openldap:2.4.12:*:*:*:*:*:*:*
openldapopenldap2.4.13cpe:2.3:a:openldap:openldap:2.4.13:*:*:*:*:*:*:*
openldapopenldap2.4.14cpe:2.3:a:openldap:openldap:2.4.14:*:*:*:*:*:*:*
openldapopenldap2.4.15cpe:2.3:a:openldap:openldap:2.4.15:*:*:*:*:*:*:*
Rows per page:
1-10 of 181

References

CVSS2

4.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:S/C:P/I:P/A:P

AI Score

9

Confidence

High

EPSS

0.004

Percentile

74.0%