Lucene search

K
cve[email protected]CVE-2013-1897
HistoryMay 13, 2013 - 11:55 p.m.

CVE-2013-1897

2013-05-1323:55:01
CWE-264
web.nvd.nist.gov
31
cve-2013-1897
389 directory server
ldap
remote attack
sensitive information
nvd

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

5.8 Medium

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

77.6%

The do_search function in ldap/servers/slapd/search.c in 389 Directory Server 1.2.x before 1.2.11.20 and 1.3.x before 1.3.0.5 does not properly restrict access to entries when the nsslapd-allow-anonymous-access configuration is set to rootdse and the BASE search scope is used, which allows remote attackers to obtain sensitive information outside of the rootDSE via a crafted LDAP search.

Affected configurations

NVD
Node
fedoraproject389_directory_serverMatch1.2.1
OR
fedoraproject389_directory_serverMatch1.2.2
OR
fedoraproject389_directory_serverMatch1.2.3
OR
fedoraproject389_directory_serverMatch1.2.5
OR
fedoraproject389_directory_serverMatch1.2.5rc1
OR
fedoraproject389_directory_serverMatch1.2.5rc2
OR
fedoraproject389_directory_serverMatch1.2.5rc3
OR
fedoraproject389_directory_serverMatch1.2.5rc4
OR
fedoraproject389_directory_serverMatch1.2.6
OR
fedoraproject389_directory_serverMatch1.2.6a2
OR
fedoraproject389_directory_serverMatch1.2.6a3
OR
fedoraproject389_directory_serverMatch1.2.6a4
OR
fedoraproject389_directory_serverMatch1.2.6rc1
OR
fedoraproject389_directory_serverMatch1.2.6rc2
OR
fedoraproject389_directory_serverMatch1.2.6rc3
OR
fedoraproject389_directory_serverMatch1.2.6rc6
OR
fedoraproject389_directory_serverMatch1.2.6rc7
OR
fedoraproject389_directory_serverMatch1.2.6.1
OR
fedoraproject389_directory_serverMatch1.2.7alpha3
OR
fedoraproject389_directory_serverMatch1.2.7.5
OR
fedoraproject389_directory_serverMatch1.2.8alpha1
OR
fedoraproject389_directory_serverMatch1.2.8alpha2
OR
fedoraproject389_directory_serverMatch1.2.8alpha3
OR
fedoraproject389_directory_serverMatch1.2.8rc1
OR
fedoraproject389_directory_serverMatch1.2.8rc2
OR
fedoraproject389_directory_serverMatch1.2.8.1
OR
fedoraproject389_directory_serverMatch1.2.8.2
OR
fedoraproject389_directory_serverMatch1.2.8.3
OR
fedoraproject389_directory_serverMatch1.2.9.9
OR
fedoraproject389_directory_serverMatch1.2.10
OR
fedoraproject389_directory_serverMatch1.2.10alpha8
OR
fedoraproject389_directory_serverMatch1.2.10rc1
OR
fedoraproject389_directory_serverMatch1.2.10.2
OR
fedoraproject389_directory_serverMatch1.2.10.3
OR
fedoraproject389_directory_serverMatch1.2.10.4
OR
fedoraproject389_directory_serverMatch1.2.10.11
OR
fedoraproject389_directory_serverMatch1.2.11.1
OR
fedoraproject389_directory_serverMatch1.2.11.5
OR
fedoraproject389_directory_serverMatch1.2.11.6
OR
fedoraproject389_directory_serverMatch1.2.11.8
OR
fedoraproject389_directory_serverMatch1.2.11.9
OR
fedoraproject389_directory_serverMatch1.2.11.10
OR
fedoraproject389_directory_serverMatch1.2.11.11
OR
fedoraproject389_directory_serverMatch1.2.11.12
OR
fedoraproject389_directory_serverMatch1.2.11.13
OR
fedoraproject389_directory_serverMatch1.2.11.14
OR
fedoraproject389_directory_serverMatch1.2.11.15
OR
fedoraproject389_directory_serverMatch1.2.11.17
OR
fedoraproject389_directory_serverMatch1.2.11.19
Node
fedoraproject389_directory_serverMatch1.3.0.2
OR
fedoraproject389_directory_serverMatch1.3.0.3
OR
fedoraproject389_directory_serverMatch1.3.0.4

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

5.8 Medium

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

77.6%