CVE-2024-8445 - CVE House
Back to Database
Status published Medium CVE-2024-8445

389-ds-base: server crash while modifying `userpassword` using malformed input (incomplete fix for cve-2024-2199)

Vulnerability Description

The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while modifying `userPassword` using malformed input.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-8445

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Directory Server 11, Red Hat Directory Server 12, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Vulnerable Versions:
3.1.1, 0:1.3.11.1-7.el7_9

Timeline

Official Publish: September 5th, 2024
Last Modified: November 6th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)