VulnerabilityModified
CVE-2015-1849
AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows attackers to obtain sensitive information via vectors involving logging the LDAP bind credential password when TRACE logging is enabled.
MEDIUM 5.9EPSS 1.72%
Does this matter?
Lower severity and a low EPSS score (1.72%). Track it; it rarely justifies an emergency change on its own.
Description
AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows attackers to obtain sensitive information via vectors involving logging the LDAP bind credential password when TRACE logging is enabled.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.72% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- redhat/jboss enterprise application platform
- Source
- secalert@redhat.com
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1199641Exploit, Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1208580Issue Tracking, Third Party Advisory
- https://github.com/wildfly-security/jboss-negotiation/commit/0dc9d191b6eb1d13b8f0189c5b02ba6576f4722eThird Party Advisory
- https://github.com/wildfly-security/jboss-negotiation/pull/21Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1199641Exploit, Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1208580Issue Tracking, Third Party Advisory
- https://github.com/wildfly-security/jboss-negotiation/commit/0dc9d191b6eb1d13b8f0189c5b02ba6576f4722eThird Party Advisory
- https://github.com/wildfly-security/jboss-negotiation/pull/21Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.