cbcvebase.
CVE-2012-4450
published 2012-10-01

CVE-2012-4450: 389 Directory Server 1.2.10 does not properly update the ACL when a DN entry is moved by a modrdn operation, which allows remote authenticated users with…

medium6CVSS 3.1
AVNACMAuSCPIPAP
389 Directory Server 1.2.10 does not properly update the ACL when a DN entry is moved by a modrdn operation, which allows remote authenticated users with certain permissions to bypass ACL restrictions and access the DN entry.

Affected

5 ranges
VendorProductVersion rangeFixed in
debian389-ds-base< 389-ds-base 1.2.11.15-1 (bookworm)389-ds-base 1.2.11.15-1 (bookworm)
fedoraproject389_directory_server
port389389-ds-base>= 0 < 1.2.11.15-11.2.11.15-1
port389389-ds-base>= 0 < 1.2.11.15-11.2.11.15-1
port389389-ds-base>= 0 < 1.2.11.15-11.2.11.15-1

CVSS provenance

nvd6.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
osv6.0MEDIUM