CVE-2014-8105

Impact:
Important
Public Date:
2015-03-05
CWE:
CWE-862->CWE-200
Bugzilla:
1167858: CVE-2014-8105 389-ds-base: information disclosure through 'cn=changelog' subtree
An information disclosure flaw was found in the way the 389 Directory Server stored information in the Changelog that is exposed via the 'cn=changelog' LDAP sub-tree. An unauthenticated user could in certain cases use this flaw to read data from the Changelog, which could include sensitive information such as plain-text passwords.

Find out more about CVE-2014-8105 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v2 metrics

Base Score 5.8
Base Metrics AV:A/AC:L/Au:N/C:P/I:P/A:P
Access Vector Adjacent Network
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 7 (389-ds-base) RHSA-2015:0416 2015-03-05
Red Hat Enterprise Linux 6 (389-ds-base) RHSA-2015:0628 2015-03-05

Acknowledgements

This issue was discovered by Petr Špaček of the Red Hat Identity Management Engineering Team.

Last Modified
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.