CVE Vulnerabilities

CVE-2015-5246

Published: Oct 06, 2017 | Modified: Apr 20, 2025
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
4.9 N/A
AV:N/AC:M/Au:S/C:P/I:P/A:N
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The LDAP Authentication functionality in Foreman might allow remote attackers with knowledge of old passwords to gain access via vectors involving the password lifetime period in Active Directory.

Affected Software

NameVendorStart VersionEnd Version
ForemanTheforeman1.9.0 (including)1.9.0 (including)

References