Redhat
Redhat 389 Directory Server: vulnerabilidades y CVE
Redhat 389 Directory Server tiene 25 vulnerabilidades publicadas, 17 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE25
Últimos 12 meses17
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-18651 | Media (5.4) | 0.28% | — | 3 ago 2026 | A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be… |
| CVE-2026-15722 | Alta (7.5) | 0.83% | — | 31 jul 2026 | A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte… |
| CVE-2026-11770 | Alta (7.5) | 0.53% | — | 31 jul 2026 | A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search… |
| CVE-2026-15041 | Baja (3.7) | 0.36% | — | 8 jul 2026 | A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for comparing password hashes instead of a constant-time comparison function. A remote attacker could… |
| CVE-2026-14969 | Media (4.4) | 0.11% | — | 7 jul 2026 | A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC operations, allowing an attacker with privileged filesystem access to… |
| CVE-2026-14940 | Media (5.3) | 0.49% | — | 7 jul 2026 | A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Distinguished Name (DN) that contains a legacy-quoted value encoding a multivalued nested Relative Distinguished Name… |
| CVE-2026-11791 | Media (5) | 0.35% | — | 18 jun 2026 | A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information nodes, bypassing the refcount-based deferred deletion used elsewhere… |
| CVE-2026-12528 | Media (5.4) | 0.23% | — | 17 jun 2026 | A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overflow writes and reads during ACI… |
| CVE-2026-11793 | Media (4.9) | 0.28% | — | 9 jun 2026 | A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-controlled algorithm ID into a 256-byte stack buffer without bounds checking when parsing… |
| CVE-2026-11790 | Media (4.9) | 0.29% | — | 9 jun 2026 | A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on the iteration count extracted from stored password hashes. A privileged attacker who can modify a… |
| CVE-2026-11789 | Media (6.5) | 0.28% | — | 9 jun 2026 | A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when computing salt length from a crafted password hash shorter than 16 bytes, causing a buffer over-read… |
| CVE-2026-11788 | Alta (7.5) | 0.56% | — | 9 jun 2026 | A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the… |
| CVE-2026-11787 | Media (6.3) | 0.18% | — | 9 jun 2026 | A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that may influence… |
| CVE-2026-11786 | Media (6.5) | 0.16% | — | 9 jun 2026 | A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute types with trailing semicolons during database import, causing an out-of-bounds read detectable… |
| CVE-2026-11785 | Media (4.3) | 0.18% | — | 9 jun 2026 | A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial stack address information to be disclosed in LDAP responses to authenticated users. |
| CVE-2026-11611 | Media (6.5) | 0.24% | — | 8 jun 2026 | A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated client stops reading sync responses, enabling denial of service.… |
| CVE-2026-9064 | Alta (7.5) | 1.1% | — | 20 may 2026 | A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a… |
| CVE-2024-6237 | Media (6.5) | 0.92% | — | 9 jul 2024 | A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while sending a specific extended search request, leading to a denial of service. |
| CVE-2024-1062 | Media (5.5) | 0.31% | — | 12 feb 2024 | A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr. |
| CVE-2022-1949 | Alta (7.5) | 1.5% | — | 2 jun 2022 | An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass.… |
| CVE-2022-0996 | Media (6.5) | 1.5% | — | 23 mar 2022 | A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication. |
| CVE-2021-3514 | Media (6.5) | 1.2% | — | 28 may 2021 | When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash. |
| CVE-2020-35518 | Media (5.3) | 1.5% | — | 26 mar 2021 | When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP… |
| CVE-2010-2222 | Alta (7.5) | 1.3% | — | 5 nov 2019 | The _ger_parse_control function in Red Hat Directory Server 8 and the 389 Directory Server allows attackers to cause a denial of service (NULL pointer dereference) via a crafted search query. |
| CVE-2018-10935 | Media (6.5) | 1.8% | — | 11 sept 2018 | A flaw was found in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with server side sort. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Redhat
Enterprise Linux · 1937Enterprise Linux Desktop · 1928Enterprise Linux Server · 1891Enterprise Linux Workstation · 1845Enterprise Linux Server AUS · 1059Enterprise Linux EUS · 787Enterprise Linux Server TUS · 768Enterprise Linux Server EUS · 622Openshift Container Platform · 328Jboss Enterprise Application Platform · 244Satellite · 239Linux · 230