« Volver al listado

CVE-2002-0045

Estado: ModificadaAlta (7.5)—

slapd in OpenLDAP 2.0 through 2.0.19 allows local users, and anonymous users before 2.0.8, to conduct a "replace" action on access controls without any values, which causes OpenLDAP to delete non-mandatory attributes that would otherwise be protected by ACLs.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2002-0045",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": true,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2002-01-31T05:00:00.000",
  "references": [
    {
      "url": "ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-001.0.txt",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000459",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://frontal2.mandriva.com/security/advisories?name=MDKSA-2002:013",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.openldap.org/lists/openldap-announce/200201/msg00002.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/5395",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.redhat.com/support/errata/RHSA-2002-014.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/3945",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBTL0201-020",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/7978",
      "source": "cve@mitre.org"
    },
    {
      "url": "ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-001.0.txt",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000459",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://frontal2.mandriva.com/security/advisories?name=MDKSA-2002:013",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openldap.org/lists/openldap-announce/200201/msg00002.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/5395",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.redhat.com/support/errata/RHSA-2002-014.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/3945",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBTL0201-020",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/7978",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "slapd in OpenLDAP 2.0 through 2.0.19 allows local users, and anonymous users before 2.0.8, to conduct a \"replace\" action on access controls without any values, which causes OpenLDAP to delete non-mandatory attributes that would otherwise be protected by ACLs."
    },
    {
      "lang": "es",
      "value": "sldap en OpenLDAP 2.0 a 2.0.19 permite a usuarios locales, y a usuarios anónimos en versiones anteriores a 2.0.8, llevar a cabo una acción \"replace\" en controles de acceso sin valores, lo que causa que OpenLDAP borre atributos no mandatorios que de otra forma estarían protegidos por listas de control de accesso (ACL)."
    }
  ],
  "lastModified": "2026-06-16T21:56:39.147",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:openldap:openldap:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5D5CCDD0-2D88-4E8A-AD04-7E6101F6690C",
              "versionEndIncluding": "2.0.19"
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "552F2E25-DDB8-49A6-844A-8520696DBE5B"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:redhat:linux:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "29B186E5-7C2F-466E-AA4A-8F2B618F8A14"
            },
            {
              "criteria": "cpe:2.3:o:redhat:linux:7.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1D46E093-1C68-43BB-B281-12117EC8DE0F"
            },
            {
              "criteria": "cpe:2.3:o:redhat:linux:7.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E562907F-D915-4030-847A-3C6834A80D4E"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}