CVE-2002-0045
Estado: ModificadaAlta (7.5)—
slapd in OpenLDAP 2.0 through 2.0.19 allows local users, and anonymous users before 2.0.8, to conduct a "replace" action on access controls without any values, which causes OpenLDAP to delete non-mandatory attributes that would otherwise be protected by ACLs.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.22%
- Percentil entre todas las CVEs puntuadas: 82
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- NVD-CWE-Other
Referencias
- ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-001.0.txt
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000459
- http://frontal2.mandriva.com/security/advisories?name=MDKSA-2002:013
- http://www.openldap.org/lists/openldap-announce/200201/msg00002.html
- http://www.osvdb.org/5395
- http://www.redhat.com/support/errata/RHSA-2002-014.html
- http://www.securityfocus.com/bid/3945
- http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBTL0201-020
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7978
- ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-001.0.txt
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000459
- http://frontal2.mandriva.com/security/advisories?name=MDKSA-2002:013
- http://www.openldap.org/lists/openldap-announce/200201/msg00002.html
- http://www.osvdb.org/5395
- http://www.redhat.com/support/errata/RHSA-2002-014.html
- http://www.securityfocus.com/bid/3945
- http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBTL0201-020
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7978
JSON original (NVD)
Mostrar
{
"id": "CVE-2002-0045",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2002-01-31T05:00:00.000",
"references": [
{
"url": "ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-001.0.txt",
"source": "cve@mitre.org"
},
{
"url": "http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000459",
"source": "cve@mitre.org"
},
{
"url": "http://frontal2.mandriva.com/security/advisories?name=MDKSA-2002:013",
"source": "cve@mitre.org"
},
{
"url": "http://www.openldap.org/lists/openldap-announce/200201/msg00002.html",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/5395",
"source": "cve@mitre.org"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2002-014.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/3945",
"source": "cve@mitre.org"
},
{
"url": "http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBTL0201-020",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/7978",
"source": "cve@mitre.org"
},
{
"url": "ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-001.0.txt",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000459",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://frontal2.mandriva.com/security/advisories?name=MDKSA-2002:013",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openldap.org/lists/openldap-announce/200201/msg00002.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/5395",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2002-014.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/3945",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBTL0201-020",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/7978",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "slapd in OpenLDAP 2.0 through 2.0.19 allows local users, and anonymous users before 2.0.8, to conduct a \"replace\" action on access controls without any values, which causes OpenLDAP to delete non-mandatory attributes that would otherwise be protected by ACLs."
},
{
"lang": "es",
"value": "sldap en OpenLDAP 2.0 a 2.0.19 permite a usuarios locales, y a usuarios anónimos en versiones anteriores a 2.0.8, llevar a cabo una acción \"replace\" en controles de acceso sin valores, lo que causa que OpenLDAP borre atributos no mandatorios que de otra forma estarían protegidos por listas de control de accesso (ACL)."
}
],
"lastModified": "2026-06-16T21:56:39.147",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:openldap:openldap:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5D5CCDD0-2D88-4E8A-AD04-7E6101F6690C",
"versionEndIncluding": "2.0.19"
},
{
"criteria": "cpe:2.3:a:openldap:openldap:2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "552F2E25-DDB8-49A6-844A-8520696DBE5B"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:redhat:linux:7.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "29B186E5-7C2F-466E-AA4A-8F2B618F8A14"
},
{
"criteria": "cpe:2.3:o:redhat:linux:7.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1D46E093-1C68-43BB-B281-12117EC8DE0F"
},
{
"criteria": "cpe:2.3:o:redhat:linux:7.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E562907F-D915-4030-847A-3C6834A80D4E"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}