SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-2746

389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), when the password of a LDAP user has been changed and audit logging is enabled, saves the new password to the log in plain text, which allows remote authenticated users…

LOW 2.1EPSS 1.33%

Does this matter?

Lower severity and a low EPSS score (1.33%). Track it; it rarely justifies an emergency change on its own.

Description

389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), when the password of a LDAP user has been changed and audit logging is enabled, saves the new password to the log in plain text, which allows remote authenticated users to read the password.

CVSS 2.0
2.1 LOWAV:N/AC:H/Au:S/C:P/I:N/A:N
EPSS
1.33% probability · 69th percentile
CISA KEV
Not listed
Weakness
CWE-310
Affected
redhat/directory server · fedoraproject/389 directory server
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.