« Back to list

Redhat

Redhat 389 Directory Server: vulnerabilities and CVEs

Redhat 389 Directory Server has 25 published vulnerabilities, 17 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs25
Last 12 months17
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-18651Medium (5.4)0.28%—Aug 3, 2026
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be…
CVE-2026-15722High (7.5)0.83%—Jul 31, 2026
A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte…
CVE-2026-11770High (7.5)0.53%—Jul 31, 2026
A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search…
CVE-2026-15041Low (3.7)0.36%—Jul 8, 2026
A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for comparing password hashes instead of a constant-time comparison function. A remote attacker could…
CVE-2026-14969Medium (4.4)0.11%—Jul 7, 2026
A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC operations, allowing an attacker with privileged filesystem access to…
CVE-2026-14940Medium (5.3)0.49%—Jul 7, 2026
A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Distinguished Name (DN) that contains a legacy-quoted value encoding a multivalued nested Relative Distinguished Name…
CVE-2026-11791Medium (5)0.35%—Jun 18, 2026
A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information nodes, bypassing the refcount-based deferred deletion used elsewhere…
CVE-2026-12528Medium (5.4)0.23%—Jun 17, 2026
A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overflow writes and reads during ACI…
CVE-2026-11793Medium (4.9)0.28%—Jun 9, 2026
A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-controlled algorithm ID into a 256-byte stack buffer without bounds checking when parsing…
CVE-2026-11790Medium (4.9)0.29%—Jun 9, 2026
A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on the iteration count extracted from stored password hashes. A privileged attacker who can modify a…
CVE-2026-11789Medium (6.5)0.28%—Jun 9, 2026
A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when computing salt length from a crafted password hash shorter than 16 bytes, causing a buffer over-read…
CVE-2026-11788High (7.5)0.56%—Jun 9, 2026
A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the…
CVE-2026-11787Medium (6.3)0.18%—Jun 9, 2026
A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that may influence…
CVE-2026-11786Medium (6.5)0.16%—Jun 9, 2026
A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute types with trailing semicolons during database import, causing an out-of-bounds read detectable…
CVE-2026-11785Medium (4.3)0.18%—Jun 9, 2026
A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial stack address information to be disclosed in LDAP responses to authenticated users.
CVE-2026-11611Medium (6.5)0.24%—Jun 8, 2026
A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated client stops reading sync responses, enabling denial of service.…
CVE-2026-9064High (7.5)1.1%—May 20, 2026
A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a…
CVE-2024-6237Medium (6.5)0.92%—Jul 9, 2024
A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while sending a specific extended search request, leading to a denial of service.
CVE-2024-1062Medium (5.5)0.31%—Feb 12, 2024
A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr.
CVE-2022-1949High (7.5)1.5%—Jun 2, 2022
An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass.…
CVE-2022-0996Medium (6.5)1.5%—Mar 23, 2022
A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication.
CVE-2021-3514Medium (6.5)1.2%—May 28, 2021
When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash.
CVE-2020-35518Medium (5.3)1.5%—Mar 26, 2021
When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP…
CVE-2010-2222High (7.5)1.3%—Nov 5, 2019
The _ger_parse_control function in Red Hat Directory Server 8 and the 389 Directory Server allows attackers to cause a denial of service (NULL pointer dereference) via a crafted search query.
CVE-2018-10935Medium (6.5)1.8%—Sep 11, 2018
A flaw was found in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with server side sort.

Other products by Redhat