CVE-2014-3562
389-ds: unauthenticated information disclosure
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote attackers to obtain sensitive replicated metadata by searching the directory.
Red Hat Directory Server 8 y 389 Directory Server, cuando depuración está habilitada, permite a atacantes remotos obtener metadatos replicados sensibles mediante la búsqueda del directorio.
It was found that when replication was enabled for each attribute in Red Hat Directory Server / 389 Directory Server, which is the default configuration, the server returned replicated metadata when the directory was searched while debugging was enabled. A remote attacker could use this flaw to disclose potentially sensitive information.
The 389 Directory Server is an LDAPv3 compliant server. The base packages include the Lightweight Directory Access Protocol server and command-line utilities for server administration. It was found that when replication was enabled for each attribute in 389 Directory Server, which is the default configuration, the server returned replicated metadata when the directory was searched while debugging was enabled. A remote attacker could use this flaw to disclose potentially sensitive information. This issue was discovered by Ludwig Krispenz of Red Hat.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-05-14 CVE Reserved
- 2014-08-08 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-201: Insertion of Sensitive Information Into Sent Data
CAPEC
References (4)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2014-1031.html | 2023-02-13 | |
http://rhn.redhat.com/errata/RHSA-2014-1032.html | 2023-02-13 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1123477 | 2014-08-07 | |
https://access.redhat.com/security/cve/CVE-2014-3562 | 2014-08-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.1 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.1" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.2 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.2" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.3 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.3" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.5 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.5" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.5 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.5" | rc1 |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.5 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.5" | rc2 |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.5 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.5" | rc3 |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.5 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.5" | rc4 |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.6 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.6" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.6 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.6" | a2 |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.6 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.6" | a3 |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.6 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.6" | a4 |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.6 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.6" | rc1 |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.6 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.6" | rc2 |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.6 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.6" | rc3 |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.6 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.6" | rc6 |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.6 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.6" | rc7 |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.6.1 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.6.1" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.7 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.7" | alpha3 |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.7.5 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.7.5" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.8 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.8" | alpha1 |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.8 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.8" | alpha2 |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.8 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.8" | alpha3 |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.8 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.8" | rc1 |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.8 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.8" | rc2 |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.8.1 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.8.1" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.8.2 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.8.2" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.8.3 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.8.3" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.9.9 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.9.9" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.10 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.10" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.10 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.10" | alpha8 |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.10 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.10" | rc1 |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.10.2 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.10.2" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.10.3 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.10.3" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.10.4 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.10.4" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.10.11 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.10.11" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.1 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.1" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.5 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.5" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.6 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.6" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.8 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.8" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.9 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.9" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.10 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.10" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.11 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.11" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.12 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.12" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.13 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.13" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.14 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.14" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.15 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.15" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.17 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.17" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.19 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.19" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.20 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.20" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.21 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.21" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.22 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.22" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.23 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.23" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.25 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.25" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.26 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.26" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.3.0.2 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.3.0.2" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.3.0.3 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.3.0.3" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.3.0.4 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.3.0.4" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.3.0.5 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.3.0.5" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.3.0.6 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.3.0.6" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.3.0.7 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.3.0.7" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.3.0.8 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.3.0.8" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Directory Server Search vendor "Redhat" for product "Directory Server" | 8.0 Search vendor "Redhat" for product "Directory Server" and version "8.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 6.0 Search vendor "Redhat" for product "Enterprise Linux" and version "6.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 7.0 Search vendor "Redhat" for product "Enterprise Linux" and version "7.0" | - |
Affected
|