Lucene search

K
ubuntucveUbuntu.comUB:CVE-2014-8105
HistoryMar 10, 2015 - 12:00 a.m.

CVE-2014-8105

2015-03-1000:00:00
ubuntu.com
ubuntu.com
13

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

0.005 Low

EPSS

Percentile

75.8%

389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does not
properly restrict access to the “cn=changelog” LDAP sub-tree, which allows
remote attackers to obtain sensitive information from the changelog via
unspecified vectors.

Bugs

Notes

Author Note
tyhicks The Red Hat bug says that FreeIPA versions 4.0+ are affected but it isn’t clear to me if it is a bug in freeipa or 389-ds-base
sbeattie further investigation doesn’t show any changes made to freeipa for this issue.

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

0.005 Low

EPSS

Percentile

75.8%