Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2013-1897

The do_search function in ldap/servers/slapd/search.c in 389 Directory Server 1.2.x before 1.2.11.20 and 1.3.x before 1.3.0.5 does not properly restrict access to entries when the nsslapd-allow-anonymous-access configuration is set to rootdse and the BASE search scope is used, which allows remote attackers to obtain sensitive information outside of the rootDSE via a crafted LDAP search.

  • Published: May 14, 2013
  • Updated: Apr 13, 2023
  • CVE: CVE-2013-1897
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 2.6
  • AV:N/AC:H/Au:N/C:P/I:N/A:N

CWEs:

Software From Fixed in
fedoraproject / 389_directory_server 1.2.5-rc4 1.2.5-rc4.x
fedoraproject / 389_directory_server 1.2.3 1.2.3.x
fedoraproject / 389_directory_server 1.2.11.9 1.2.11.9.x
fedoraproject / 389_directory_server 1.2.5-rc1 1.2.5-rc1.x
fedoraproject / 389_directory_server 1.2.8-rc2 1.2.8-rc2.x
fedoraproject / 389_directory_server 1.2.8-rc1 1.2.8-rc1.x
fedoraproject / 389_directory_server 1.2.9.9 1.2.9.9.x
fedoraproject / 389_directory_server 1.2.11.8 1.2.11.8.x
fedoraproject / 389_directory_server 1.2.8.3 1.2.8.3.x
fedoraproject / 389_directory_server 1.2.6-rc3 1.2.6-rc3.x
fedoraproject / 389_directory_server 1.2.6-a3 1.2.6-a3.x
fedoraproject / 389_directory_server 1.2.10 1.2.10.x
fedoraproject / 389_directory_server 1.2.11.13 1.2.11.13.x
fedoraproject / 389_directory_server 1.2.6-rc1 1.2.6-rc1.x
fedoraproject / 389_directory_server 1.2.8.2 1.2.8.2.x
fedoraproject / 389_directory_server 1.2.7.5 1.2.7.5.x
fedoraproject / 389_directory_server 1.2.1 1.2.1.x
fedoraproject / 389_directory_server 1.2.2 1.2.2.x
fedoraproject / 389_directory_server 1.2.5 1.2.5.x
fedoraproject / 389_directory_server 1.2.8-alpha2 1.2.8-alpha2.x
fedoraproject / 389_directory_server 1.2.6-rc6 1.2.6-rc6.x
fedoraproject / 389_directory_server 1.2.11.17 1.2.11.17.x
fedoraproject / 389_directory_server 1.2.10-rc1 1.2.10-rc1.x
fedoraproject / 389_directory_server 1.2.11.19 1.2.11.19.x
fedoraproject / 389_directory_server 1.2.11.12 1.2.11.12.x
fedoraproject / 389_directory_server 1.2.8-alpha3 1.2.8-alpha3.x
fedoraproject / 389_directory_server 1.2.6.1 1.2.6.1.x
fedoraproject / 389_directory_server 1.2.11.6 1.2.11.6.x
fedoraproject / 389_directory_server 1.2.11.10 1.2.11.10.x
fedoraproject / 389_directory_server 1.2.5-rc3 1.2.5-rc3.x
fedoraproject / 389_directory_server 1.2.6-a4 1.2.6-a4.x
fedoraproject / 389_directory_server 1.2.11.11 1.2.11.11.x
fedoraproject / 389_directory_server 1.2.10.3 1.2.10.3.x
fedoraproject / 389_directory_server 1.2.11.1 1.2.11.1.x
fedoraproject / 389_directory_server 1.2.11.5 1.2.11.5.x
fedoraproject / 389_directory_server 1.2.10.4 1.2.10.4.x
fedoraproject / 389_directory_server 1.2.5-rc2 1.2.5-rc2.x
fedoraproject / 389_directory_server 1.2.10.11 1.2.10.11.x
fedoraproject / 389_directory_server 1.2.10.2 1.2.10.2.x
fedoraproject / 389_directory_server 1.2.8-alpha1 1.2.8-alpha1.x
fedoraproject / 389_directory_server 1.2.6-rc2 1.2.6-rc2.x
fedoraproject / 389_directory_server 1.2.6-a2 1.2.6-a2.x
fedoraproject / 389_directory_server 1.2.6 1.2.6.x
fedoraproject / 389_directory_server 1.2.6-rc7 1.2.6-rc7.x
fedoraproject / 389_directory_server 1.2.11.14 1.2.11.14.x
fedoraproject / 389_directory_server 1.2.8.1 1.2.8.1.x
fedoraproject / 389_directory_server 1.2.10-alpha8 1.2.10-alpha8.x
fedoraproject / 389_directory_server 1.2.11.15 1.2.11.15.x
fedoraproject / 389_directory_server 1.2.7-alpha3 1.2.7-alpha3.x
fedoraproject / 389_directory_server 1.3.0.3 1.3.0.3.x
fedoraproject / 389_directory_server 1.3.0.4 1.3.0.4.x
fedoraproject / 389_directory_server 1.3.0.2 1.3.0.2.x