VendorsRed Hatdirectory_server12.0
Vulnerabilities

Red Hat Directory Server 12.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

21CVEs
CVE-2022-1949
An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass. This may allow any remote unauthenticated user to issue a filter that allows searching for database items they do not have access to, including but not limited to potentially userPassword hashes and other sensitive data.
Published 2022-06-01 · Modified
7.5EPSS 0.015
CVE-2026-9064
389-ds-base: 389-ds-base: unbounded ldap controls count in get_ldapmessage_controls_ext() causes cpu and heap amplification (remote dos)
Published 2026-05-20 · Modified
7.5EPSS 0.011
CVE-2026-15722
389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica id parsing
Published 2026-07-31 · Modified
7.5EPSS 0.008
CVE-2026-11788
389-ds-base: 389-ds-base: null pointer dereference in deref control plugin ber parser
Published 2026-06-09 · Modified
7.5EPSS 0.006
CVE-2026-11770
389-ds-base: 389-ds-base: pre-auth ldap filter injection in cleanallruv status check
Published 2026-07-31 · Modified
7.5EPSS 0.005
CVE-2022-2850
A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. This CVE is assigned against an incomplete fix of CVE-2021-3514.
Published 2022-10-14 · Modified
6.5EPSS 0.013
CVE-2024-6237
389-ds-base: unauthenticated user can trigger a dos by sending a specific extended search request
Published 2024-07-09 · Modified
6.5EPSS 0.009
CVE-2026-11789
389-ds-base: 389-ds-base: smd5 password storage plugin salt length integer underflow crash
Published 2026-06-09 · Modified
6.5EPSS 0.003
CVE-2026-11611
389-ds-base: 389-ds-base: content sync plugin unbounded queue growth and race conditions
Published 2026-06-08 · Modified
6.5EPSS 0.002
CVE-2026-11786
389-ds-base: 389-ds-base: heap out-of-bounds read in ldif parser str2entry_state_information_from_type()
Published 2026-06-09 · Modified
6.5EPSS 0.002
CVE-2026-11787
389-ds-base: 389-ds-base: heap buffer over-read in ldap_utf8prev() via str2simple filter parsing
Published 2026-06-09 · Modified
6.3EPSS 0.002
CVE-2024-1062
389-ds-base: a heap overflow leading to denail-of-servce while writing a value larger than 256 chars (in log_entry_attr)
Published 2024-02-12 · Modified
5.5EPSS 0.003
CVE-2023-1055
A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attribute which could lead into sensitive information leaked. An attacker with a local account where the cockpit-389-ds is running can list the processes and display the hashed passwords. The highest threat from this vulnerability is to data confidentiality.
Published 2023-02-27 · Modified
5.5EPSS 0.002
CVE-2026-18651
389-ds-base: 389-ds-base: sasl plain bind installs connection credentials before account-lock check, allowing continued access as a locked account
Published 2026-08-03 · Analyzed
5.4EPSS 0.003
CVE-2026-12528
389-ds-base: 389-ds-base: heap-buffer-overflows in __aclp__normalize_acltxt()
Published 2026-06-17 · Analyzed
5.4EPSS 0.002
CVE-2026-14940
389-ds-base: 389-ds-base: heap-buffer-overflow in dn normalization via quoted multivalued rdn
Published 2026-07-07 · Analyzed
5.3EPSS 0.005
CVE-2026-11791
389-ds-base: 389-ds-base: use-after-free in schema reload via attr_syntax_swap_ht()
Published 2026-06-18 · Modified
5.0EPSS 0.004
CVE-2026-11790
389-ds-base: 389-ds-base: pbkdf2 password storage plugin unbounded iteration count denial of service
Published 2026-06-09 · Modified
4.9EPSS 0.003
CVE-2026-14969
389-ds-base: 389-ds-base: static initialization vector in aes-cbc/3des-cbc attribute encryption
Published 2026-07-07 · Analyzed
4.4EPSS 0.001
CVE-2026-11785
389-ds-base: 389-ds-base: partial stack address information leak via ber_printf type confusion in sso token handler
Published 2026-06-09 · Modified
4.3EPSS 0.002
CVE-2026-15041
389-ds-base: 389-ds-base: non-constant-time comparison in pbkdf2-sha256 password verification
Published 2026-07-08 · Analyzed
3.7EPSS 0.004