389-ds-base before versions 1.3.8.5, 1.4.0.12 is vulnerable to a Cleartext...
Vulnerability Description
389-ds-base before versions 1.3.8.5, 1.4.0.12 is vulnerable to a Cleartext Storage of Sensitive Information. By default, when the Replica and/or retroChangeLog plugins are enabled, 389-ds-base stores passwords in plaintext format in their respective changelog files. An attacker with sufficiently high privileges, such as root or Directory Manager, can query these files in order to retrieve plaintext passwords.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-10871
Credits & Attribution
No credits recorded in the NVD database.
References
More from [UNKNOWN]
View All →Affected Vendor
[UNKNOWN]
View all reports →