CVE Vulnerabilities

CVE-2014-9713

Published: Apr 01, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The default slapd configuration in the Debian openldap package 2.4.23-3 through 2.4.39-1.1 allows remote authenticated users to modify the users permissions and other user attributes via unspecified vectors.

Affected Software

NameVendorStart VersionEnd Version
OpenldapOpenldap2.4.23 (including)2.4.23 (including)
OpenldapOpenldap2.4.24 (including)2.4.24 (including)
OpenldapOpenldap2.4.25 (including)2.4.25 (including)
OpenldapOpenldap2.4.26 (including)2.4.26 (including)
OpenldapOpenldap2.4.27 (including)2.4.27 (including)
OpenldapOpenldap2.4.28 (including)2.4.28 (including)
OpenldapOpenldap2.4.29 (including)2.4.29 (including)
OpenldapOpenldap2.4.30 (including)2.4.30 (including)
OpenldapOpenldap2.4.31 (including)2.4.31 (including)
OpenldapOpenldap2.4.32 (including)2.4.32 (including)
OpenldapOpenldap2.4.33 (including)2.4.33 (including)
OpenldapOpenldap2.4.34 (including)2.4.34 (including)
OpenldapOpenldap2.4.35 (including)2.4.35 (including)
OpenldapOpenldap2.4.36 (including)2.4.36 (including)
OpenldapOpenldap2.4.37 (including)2.4.37 (including)
OpenldapOpenldap2.4.38 (including)2.4.38 (including)
OpenldapOpenldap2.4.39 (including)2.4.39 (including)
OpenldapUbuntudevel*
OpenldapUbuntuesm-infra-legacy/trusty*
OpenldapUbuntuprecise*
OpenldapUbuntutrusty*
OpenldapUbuntutrusty/esm*
OpenldapUbuntuupstream*
OpenldapUbuntuutopic*
OpenldapUbuntuvivid*
OpenldapUbuntuvivid/stable-phone-overlay*
OpenldapUbuntuvivid/ubuntu-core*

References