Port389 389-Ds-Base vulnerabilities
51 known vulnerabilities affecting port389/389-ds-base.
Total CVEs
51
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH18MEDIUM28LOW3
Vulnerabilities
Page 1 of 3
CVE-2025-2487MEDIUMCVSS 4.9≥ 0, < 3.1.2+dfsg1-12025-03-18
CVE-2025-2487 [MEDIUM] CVE-2025-2487: A flaw was found in the 389-ds-base LDAP Server
A flaw was found in the 389-ds-base LDAP Server. This issue occurs when issuing a Modify DN LDAP operation through the ldap protocol, when the function return value is not tested and a NULL pointer is dereferenced. If a privileged user performs a ldap MODDN operation after a failed operation, it could lead to a Denial of Service (DoS) or system crash.
osv
CVE-2024-8445MEDIUMCVSS 5.7≥ 0, < 1.4.4.11-2+deb11u1≥ 0, < 2.0.11-12024-09-05
CVE-2024-8445 [MEDIUM] CVE-2024-8445: The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios
The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while modifying `userPassword` using malformed input.
osv
CVE-2024-6237MEDIUMCVSS 6.5≥ 0, < 2.4.5+dfsg1-12024-07-09
CVE-2024-6237 [MEDIUM] CVE-2024-6237: A flaw was found in the 389 Directory Server
A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while sending a specific extended search request, leading to a denial of service.
osv
CVE-2024-5953MEDIUMCVSS 5.7≥ 0, < 1.4.4.11-2+deb11u1≥ 0, < 2.3.1+dfsg1-1+deb12u1+1 more2024-06-18
CVE-2024-5953 [MEDIUM] CVE-2024-5953: A denial of service vulnerability was found in the 389-ds-base LDAP server
A denial of service vulnerability was found in the 389-ds-base LDAP server. This issue may allow an authenticated user to cause a server denial of service while attempting to log in with a user with a malformed hash in their password.
osv
CVE-2024-3657HIGHCVSS 7.5≥ 0, < 1.4.4.11-2+deb11u1≥ 0, < 2.3.1+dfsg1-1+deb12u1+1 more2024-05-28
CVE-2024-3657 [HIGH] CVE-2024-3657: A flaw was found in 389-ds-base
A flaw was found in 389-ds-base. A specially-crafted LDAP query can potentially cause a failure on the directory server, leading to a denial of service
osv
CVE-2024-2199MEDIUMCVSS 5.7≥ 0, < 1.4.4.11-2+deb11u1≥ 0, < 2.3.1+dfsg1-1+deb12u1+1 more2024-05-28
CVE-2024-2199 [MEDIUM] CVE-2024-2199: A denial of service vulnerability was found in 389-ds-base ldap server
A denial of service vulnerability was found in 389-ds-base ldap server. This issue may allow an authenticated user to cause a server crash while modifying `userPassword` using malformed input.
osv
CVE-2024-1062MEDIUMCVSS 5.5≥ 0, < 2.3.4+dfsg1-12024-02-12
CVE-2024-1062 [MEDIUM] CVE-2024-1062: A heap overflow flaw was found in 389-ds-base
A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr.
osv
CVE-2023-1055MEDIUMCVSS 5.5≥ 0, < 2.3.4+dfsg1-12023-02-27
CVE-2023-1055 [MEDIUM] CVE-2023-1055: A flaw was found in RHDS 11 and RHDS 12
A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attribute which could lead into sensitive information leaked. An attacker with a local account where the cockpit-389-ds is running can list the processes and display the hashed passwords. The highest threat from this vulnerability is to data confidentiality.
osv
CVE-2022-2850MEDIUMCVSS 6.5≥ 2.0.0, ≤ 2.4.12022-10-14
CVE-2022-2850 [MEDIUM] CVE-2022-2850: A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticate
A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. This CVE is assigned against an incomplete fix of CVE-2021-3514.
cvelistv5nvdosv
CVE-2022-1949HIGHCVSS 7.5v389-ds-base-2.02022-06-01
CVE-2022-1949 [HIGH] CVE-2022-1949: An access control bypass vulnerability found in 389-ds-base
An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass. This may allow any remote unauthenticated user to issue a filter that allows searching for database items they do not have access to, including but not limited to potentially userPassw
cvelistv5osv
CVE-2021-3652MEDIUMCVSS 6.5fixed in 2.0.7v389-ds-base 2.0.72022-04-18
CVE-2021-3652 [MEDIUM] CWE-287 CVE-2021-3652: A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, either accidentally
A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, either accidentally or maliciously, then instead of being inactive, any password will successfully match during authentication. This flaw allows an attacker to successfully authenticate as a user whose password was disabled.
cvelistv5nvdosv
CVE-2022-0996MEDIUMCVSS 6.5v1.42022-03-23
CVE-2022-0996 [MEDIUM] CVE-2022-0996: A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication
A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication.
cvelistv5osv
CVE-2022-0918HIGHCVSS 7.5v1.4.0v1.42022-03-16
CVE-2022-0918 [HIGH] CVE-2022-0918: A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker w
A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service. The denial of service is triggered by a single message sent over a TCP connection, no bind or other authentication is required. The message triggers a segmentation fault that results in slapd crash
cvelistv5nvdosv
CVE-2021-4091HIGHCVSS 7.5fixed in 1.3.10.2v389-ds-base-1.3.10.22022-02-18
CVE-2021-4091 [HIGH] CWE-415 CVE-2021-4091: A double-free was found in the way 389-ds-base handles virtual attributes context in persistent sear
A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash.
cvelistv5nvdosv
CVE-2021-3514MEDIUMCVSS 6.5v389-ds-base 1.4.32021-05-28
CVE-2021-3514 [MEDIUM] CWE-476 CVE-2021-3514: When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing
When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash.
cvelistv5osv
CVE-2020-35518MEDIUMCVSS 5.3v389-ds-base 2.0.3, 389-ds-base 1.4.4.13, 389-ds-base 1.4.3.192021-03-26
CVE-2020-35518 [MEDIUM] CWE-200 CVE-2020-35518: When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not
When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.
cvelistv5osv
CVE-2019-10224MEDIUMCVSS 4.6≥ 0, < 1.4.1.5-12019-11-25
CVE-2019-10224 [MEDIUM] CVE-2019-10224: A flaw has been found in 389-ds-base versions 1
A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information.
osv
CVE-2019-14824MEDIUMCVSS 6.5≥ 0, < 1.4.2.4-12019-11-08
CVE-2019-14824 [MEDIUM] CVE-2019-14824: A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values
A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.
osv
CVE-2019-3883HIGHCVSS 7.5≥ 0, < 1.4.1.5-12019-04-17
CVE-2019-3883 [HIGH] CVE-2019-3883: In 389-ds-base up to version 1
In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout' seconds. However this timeout applies only for un-encrypted requests. Connections using SSL/TLS are not taking this timeout into account during reads, and may hang longer.An unauthenticated attacker could repeatedly create hanging LDAP requests to hang all the workers, resulting in
osv
CVE-2018-14648HIGHCVSS 7.5≥ 0, < 1.4.0.18-12018-09-28
CVE-2018-14648 [HIGH] CVE-2018-14648: A flaw was found in 389 Directory Server
A flaw was found in 389 Directory Server. A specially crafted search query could lead to excessive CPU consumption in the do_search() function. An unauthenticated attacker could use this flaw to provoke a denial of service.
osv
1 / 3Next →