Lucene search

K
cve[email protected]CVE-2012-2746
HistoryJul 03, 2012 - 4:40 p.m.

CVE-2012-2746

2012-07-0316:40:34
CWE-310
web.nvd.nist.gov
24
389 directory server
red hat directory server
cve-2012-2746
password security
plaintext logging
ldap
audit logging

2.1 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:S/C:P/I:N/A:N

6.2 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

58.6%

389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), when the password of a LDAP user has been changed and audit logging is enabled, saves the new password to the log in plain text, which allows remote authenticated users to read the password.

Affected configurations

NVD
Node
redhatdirectory_serverRange8.2
OR
redhatdirectory_serverMatch7.1
OR
redhatdirectory_serverMatch8.0
OR
redhatdirectory_serverMatch8.1
Node
fedoraproject389_directory_serverRange1.2.11.5
OR
fedoraproject389_directory_serverMatch1.2.1
OR
fedoraproject389_directory_serverMatch1.2.2
OR
fedoraproject389_directory_serverMatch1.2.3
OR
fedoraproject389_directory_serverMatch1.2.5
OR
fedoraproject389_directory_serverMatch1.2.5rc1
OR
fedoraproject389_directory_serverMatch1.2.5rc2
OR
fedoraproject389_directory_serverMatch1.2.5rc3
OR
fedoraproject389_directory_serverMatch1.2.5rc4
OR
fedoraproject389_directory_serverMatch1.2.6
OR
fedoraproject389_directory_serverMatch1.2.6a2
OR
fedoraproject389_directory_serverMatch1.2.6a3
OR
fedoraproject389_directory_serverMatch1.2.6a4
OR
fedoraproject389_directory_serverMatch1.2.6rc1
OR
fedoraproject389_directory_serverMatch1.2.6rc2
OR
fedoraproject389_directory_serverMatch1.2.6rc3
OR
fedoraproject389_directory_serverMatch1.2.6rc6
OR
fedoraproject389_directory_serverMatch1.2.6rc7
OR
fedoraproject389_directory_serverMatch1.2.6.1
OR
fedoraproject389_directory_serverMatch1.2.7alpha3
OR
fedoraproject389_directory_serverMatch1.2.7.5
OR
fedoraproject389_directory_serverMatch1.2.8alpha1
OR
fedoraproject389_directory_serverMatch1.2.8alpha2
OR
fedoraproject389_directory_serverMatch1.2.8alpha3
OR
fedoraproject389_directory_serverMatch1.2.8rc1
OR
fedoraproject389_directory_serverMatch1.2.8rc2
OR
fedoraproject389_directory_serverMatch1.2.8.1
OR
fedoraproject389_directory_serverMatch1.2.8.2
OR
fedoraproject389_directory_serverMatch1.2.8.3
OR
fedoraproject389_directory_serverMatch1.2.9.9
OR
fedoraproject389_directory_serverMatch1.2.10alpha8
OR
fedoraproject389_directory_serverMatch1.2.10rc1
OR
fedoraproject389_directory_serverMatch1.2.10.1
OR
fedoraproject389_directory_serverMatch1.2.10.2
OR
fedoraproject389_directory_serverMatch1.2.10.3
OR
fedoraproject389_directory_serverMatch1.2.10.4
OR
fedoraproject389_directory_serverMatch1.2.10.7
OR
fedoraproject389_directory_serverMatch1.2.11.1

2.1 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:S/C:P/I:N/A:N

6.2 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

58.6%