An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that…
An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass. This may allow any remote unauthenticated user to issue a filter that allows searching for database items they do not have access to, including but not limited to potentially userPassword hashes and other sensitive data.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
https://cwe.mitre.org/data/definitions/639.html →Open in CWE collection →The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
https://cwe.mitre.org/data/definitions/863.html →Open in CWE collection →| Product | Vendor | Status |
|---|---|---|
| 389-ds-base | Tracked | |
| 389-ds-base | Tracked | |
| 389-ds-base | Tracked | |
| 389-ds-base | Tracked | |
| 389-ds-base | Tracked | |
| 389-ds-base | Tracked | |
| 389-ds-base | Tracked | |
| 389-ds-base | Tracked | |
| 389-ds-base | Tracked | |
| 389-ds-base | Tracked | |
| 389-ds-base | Tracked | |
| 389-ds-base | Tracked | |
| 389-ds-base | Tracked | |
| 389_directory_server | * | Tracked |
| directory_server | * | Tracked |
| enterprise_linux | * | Tracked |
| fedora | * | Tracked |