389-ds-base
by 389 Ds Base
CVEs (24)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-10224 | Med | 0.30 | 4.6 | 0.00 | Nov 25, 2019 | A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard… | ||
| CVE-2026-14969 | mod | 0.29 | 4.4 | 0.00 | Jul 7, 2026 | 389-ds-base: 389-ds-base: Static initialization vector in AES-CBC/3DES-CBC attribute encryption | ||
| CVE-2018-10871 | Low | 0.25 | 3.8 | 0.01 | Jul 18, 2018 | 389-ds-base before versions 1.3.8.5, 1.4.0.12 is vulnerable to a Cleartext Storage of Sensitive Information. By default, when the Replica and/or retroChangeLog plugins are enabled, 389-ds-base stores passwords in plaintext format in their respective changelog files. An attacker… | ||
| CVE-2026-15041 | low | 0.24 | 3.7 | 0.00 | Jul 8, 2026 | 389-ds-base: 389-ds-base: Non-constant-time comparison in PBKDF2-SHA256 password verification |
- risk 0.30cvss 4.6epss 0.00
A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard…
- risk 0.29cvss 4.4epss 0.00
389-ds-base: 389-ds-base: Static initialization vector in AES-CBC/3DES-CBC attribute encryption
- risk 0.25cvss 3.8epss 0.01
389-ds-base before versions 1.3.8.5, 1.4.0.12 is vulnerable to a Cleartext Storage of Sensitive Information. By default, when the Replica and/or retroChangeLog plugins are enabled, 389-ds-base stores passwords in plaintext format in their respective changelog files. An attacker…
- risk 0.24cvss 3.7epss 0.00
389-ds-base: 389-ds-base: Non-constant-time comparison in PBKDF2-SHA256 password verification
Page 2 of 2