VendorsRed Hatdirectory_server11.0
Vulnerabilities

Red Hat Directory Server 11.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18CVEs
CVE-2022-1949
An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass. This may allow any remote unauthenticated user to issue a filter that allows searching for database items they do not have access to, including but not limited to potentially userPassword hashes and other sensitive data.
Published 2022-06-01 · Modified
7.5EPSS 0.015
CVE-2026-15722
389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica id parsing
Published 2026-07-31 · Modified
7.5EPSS 0.008
CVE-2026-9064
389-ds-base: 389-ds-base: unbounded ldap controls count in get_ldapmessage_controls_ext() causes cpu and heap amplification (remote dos)
Published 2026-05-20 · Modified
7.5EPSS 0.008
CVE-2026-11788
389-ds-base: 389-ds-base: null pointer dereference in deref control plugin ber parser
Published 2026-06-09 · Modified
7.5EPSS 0.006
CVE-2026-11770
389-ds-base: 389-ds-base: pre-auth ldap filter injection in cleanallruv status check
Published 2026-07-31 · Modified
7.5EPSS 0.005
CVE-2022-2850
A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. This CVE is assigned against an incomplete fix of CVE-2021-3514.
Published 2022-10-14 · Modified
6.5EPSS 0.013
CVE-2026-11789
389-ds-base: 389-ds-base: smd5 password storage plugin salt length integer underflow crash
Published 2026-06-09 · Modified
6.5EPSS 0.003
CVE-2026-11611
389-ds-base: 389-ds-base: content sync plugin unbounded queue growth and race conditions
Published 2026-06-08 · Modified
6.5EPSS 0.002
CVE-2026-11786
389-ds-base: 389-ds-base: heap out-of-bounds read in ldif parser str2entry_state_information_from_type()
Published 2026-06-09 · Modified
6.5EPSS 0.002
CVE-2026-11787
389-ds-base: 389-ds-base: heap buffer over-read in ldap_utf8prev() via str2simple filter parsing
Published 2026-06-09 · Modified
6.3EPSS 0.002
CVE-2026-12528
389-ds-base: 389-ds-base: heap-buffer-overflows in __aclp__normalize_acltxt()
Published 2026-06-17 · Analyzed
5.4EPSS 0.002
CVE-2026-18651
389-ds-base: 389-ds-base: sasl plain bind installs connection credentials before account-lock check, allowing continued access as a locked account
Published 2026-08-03 · Analyzed
5.4EPSS 0.002
CVE-2020-35518
When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.
Published 2021-03-26 · Modified
5.3EPSS 0.015
CVE-2026-14940
389-ds-base: 389-ds-base: heap-buffer-overflow in dn normalization via quoted multivalued rdn
Published 2026-07-07 · Analyzed
5.3EPSS 0.005
CVE-2026-11791
389-ds-base: 389-ds-base: use-after-free in schema reload via attr_syntax_swap_ht()
Published 2026-06-18 · Modified
5.0EPSS 0.002
CVE-2026-11790
389-ds-base: 389-ds-base: pbkdf2 password storage plugin unbounded iteration count denial of service
Published 2026-06-09 · Modified
4.9EPSS 0.003
CVE-2026-14969
389-ds-base: 389-ds-base: static initialization vector in aes-cbc/3des-cbc attribute encryption
Published 2026-07-07 · Analyzed
4.4EPSS 0.001
CVE-2026-15041
389-ds-base: 389-ds-base: non-constant-time comparison in pbkdf2-sha256 password verification
Published 2026-07-08 · Analyzed
3.7EPSS 0.004