CVE-2015-1849Sensitive Information Exposure in Redhat Jboss Enterprise Application Platform

Severity
5.9MEDIUMNVD
EPSS
0.3%
top 46.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 19
Latest updateMay 17

Description

AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows attackers to obtain sensitive information via vectors involving logging the LDAP bind credential password when TRACE logging is enabled.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-6hhx-86qx-9ffc: AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 62022-05-17
CVEList
CVE-2015-1849: AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 62017-09-19

📋Vendor Advisories

1
Red Hat
EAP: LDAP bind password is being logged with TRACE log level2015-03-23

💬Community

1
Bugzilla
CVE-2015-1849 JBoss EAP: LDAP bind password is being logged with TRACE log level2015-04-02
CVE-2015-1849 — Sensitive Information Exposure | cvebase