Lucene search

K
redhatRedHatRHSA-2021:2027
HistoryMay 19, 2021 - 7:06 a.m.

(RHSA-2021:2027) Important: ipa security update

2021-05-1907:06:37
access.redhat.com
39
red hat
identity management
security update
authentication
authorization
cve-2021-3480
centralized authentication
enterprise environments
cloud-based

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

50.0%

Red Hat Identity Management (IdM) is a centralized authentication, identity management, and authorization solution for both traditional and cloud-based enterprise environments.

Security Fix(es):

  • slapi-nis: NULL dereference (DoS) with specially crafted Binding DN (CVE-2021-3480)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

OSVersionArchitecturePackageVersionFilename
RedHatanyppc64leipa-idoverride-memberof-plugin< 0.0.4-6.module+el8.1.0+4098+f286395eipa-idoverride-memberof-plugin-0.0.4-6.module+el8.1.0+4098+f286395e.ppc64le.rpm
RedHatanyx86_64opendnssec-debuginfo< 1.4.14-1.module+el8.1.0+4098+f286395eopendnssec-debuginfo-1.4.14-1.module+el8.1.0+4098+f286395e.x86_64.rpm
RedHatanyaarch64bind-dyndb-ldap-debuginfo< 11.1-14.module+el8.1.0+4098+f286395ebind-dyndb-ldap-debuginfo-11.1-14.module+el8.1.0+4098+f286395e.aarch64.rpm
RedHatanyppc64lesofthsm-debugsource< 2.4.0-2.module+el8.1.0+4098+f286395esofthsm-debugsource-2.4.0-2.module+el8.1.0+4098+f286395e.ppc64le.rpm
RedHatanynoarchpython3-ipaclient< 4.8.0-13.module+el8.1.0+4923+c6efe041python3-ipaclient-4.8.0-13.module+el8.1.0+4923+c6efe041.noarch.rpm
RedHatanyaarch64ipa-server-debuginfo< 4.8.0-13.module+el8.1.0+4923+c6efe041ipa-server-debuginfo-4.8.0-13.module+el8.1.0+4923+c6efe041.aarch64.rpm
RedHatanyppc64leopendnssec-debugsource< 1.4.14-1.module+el8.1.0+4098+f286395eopendnssec-debugsource-1.4.14-1.module+el8.1.0+4098+f286395e.ppc64le.rpm
RedHatanyx86_64ipa-debuginfo< 4.8.0-13.module+el8.1.0+4923+c6efe041ipa-debuginfo-4.8.0-13.module+el8.1.0+4923+c6efe041.x86_64.rpm
RedHatanyx86_64slapi-nis-debugsource< 0.56.3-3.module+el8.1.0+10781+dffa5bcaslapi-nis-debugsource-0.56.3-3.module+el8.1.0+10781+dffa5bca.x86_64.rpm
RedHatanyaarch64slapi-nis-debuginfo< 0.56.3-3.module+el8.1.0+10781+dffa5bcaslapi-nis-debuginfo-0.56.3-3.module+el8.1.0+10781+dffa5bca.aarch64.rpm
Rows per page:
1-10 of 1091

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

50.0%