CVE Vulnerabilities

CVE-2015-5246

Published: Oct 06, 2017 | Modified: Nov 01, 2017
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
4.9 N/A
AV:N/AC:M/Au:S/C:P/I:P/A:N
RedHat/V3
Ubuntu

The LDAP Authentication functionality in Foreman might allow remote attackers with knowledge of old passwords to gain access via vectors involving the password lifetime period in Active Directory.

Affected Software

Name Vendor Start Version End Version
Foreman Theforeman 1.9.0 (including) 1.9.0 (including)

References