V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2022-1949
AST
High

An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that…

CVSS
7.4
High
EPSS
0.01
p68
Published
2022-01-01
Updated
2022-01-01
Description

An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass. This may allow any remote unauthenticated user to issue a filter that allows searching for database items they do not have access to, including but not limited to potentially userPassword hashes and other sensitive data.

Tags · CWE
Pre-auth
CWE-639
CWE-863
Affected products
389_directory_server 1.3.0.0–2.0.0
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Timeline
2022-01-01
Published
2022-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: H
High (H)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.014 · p68
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
389-ds-baseTracked
389-ds-baseTracked
389-ds-baseTracked
389-ds-baseTracked
389-ds-baseTracked
389-ds-baseTracked
389-ds-baseTracked
389-ds-baseTracked
389-ds-baseTracked
389-ds-baseTracked
389-ds-baseTracked
389-ds-baseTracked
389-ds-baseTracked
389_directory_server*Tracked
directory_server*Tracked
enterprise_linux*Tracked
fedora*Tracked
Source databases
AST
DEB
CVE
UBU
Related vulnerabilities