CVE Vulnerabilities

CVE-2015-6538

Published: Dec 27, 2015 | Modified: Apr 12, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The login page in Epiphany Cardio Server 3.3, 4.0, and 4.1 mishandles authentication requests, which allows remote attackers to conduct LDAP injection attacks, and consequently bypass intended access restrictions, via a crafted URL.

Affected Software

NameVendorStart VersionEnd Version
Cardio_serverEphiphanyheathdata3.3 (including)3.3 (including)
Cardio_serverEphiphanyheathdata4.0 (including)4.0 (including)
Cardio_serverEphiphanyheathdata4.1 (including)4.1 (including)

References