VYPR

389-ds-base

by 389 Ds Base

Source repositories

CVEs (24)

  • CVE-2019-10224MedNov 25, 2019
    risk 0.30cvss 4.6epss 0.00

    A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard…

  • CVE-2026-14969MedJul 7, 2026
    risk 0.29cvss 4.4epss 0.00

    A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC operations, allowing an attacker with privileged filesystem access to detect plaintext equality across encrypted entries by…

  • CVE-2018-10871LowJul 18, 2018
    risk 0.25cvss 3.8epss 0.01

    389-ds-base before versions 1.3.8.5, 1.4.0.12 is vulnerable to a Cleartext Storage of Sensitive Information. By default, when the Replica and/or retroChangeLog plugins are enabled, 389-ds-base stores passwords in plaintext format in their respective changelog files. An attacker…

  • CVE-2020-35518MedMar 26, 2021
    risk 0.00cvss 5.3epss 0.02

    When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.

Page 2 of 2