Executive Summary

Informations
Name CVE-2012-2746 First vendor Publication 2012-07-03
Vendor Cve Last vendor Modification 2017-09-19

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:H/Au:S/C:P/I:N/A:N)
Cvss Base Score 2.1 Attack Range Network
Cvss Impact Score 2.9 Attack Complexity High
Cvss Expoit Score 3.9 Authentication Requires single instance
Calculate full CVSS 2.0 Vectors scores

Detail

389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), when the password of a LDAP user has been changed and audit logging is enabled, saves the new password to the log in plain text, which allows remote authenticated users to read the password.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2746

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-310 Cryptographic Issues

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:19241
 
Oval ID: oval:org.mitre.oval:def:19241
Title: HP-UX Directory Server, Remote Disclosure of Information
Description: 389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), when the password of a LDAP user has been changed and audit logging is enabled, saves the new password to the log in plain text, which allows remote authenticated users to read the password.
Family: unix Class: vulnerability
Reference(s): CVE-2012-2746
Version: 10
Platform(s): HP-UX 11
Product(s):
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:21476
 
Oval ID: oval:org.mitre.oval:def:21476
Title: RHSA-2012:0997: 389-ds-base security update (Moderate)
Description: 389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), when the password of a LDAP user has been changed and audit logging is enabled, saves the new password to the log in plain text, which allows remote authenticated users to read the password.
Family: unix Class: patch
Reference(s): RHSA-2012:0997-01
CESA-2012:0997
CVE-2012-2678
CVE-2012-2746
Version: 29
Platform(s): Red Hat Enterprise Linux 6
CentOS Linux 6
Product(s): 389-ds-base
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:23785
 
Oval ID: oval:org.mitre.oval:def:23785
Title: ELSA-2012:0997: 389-ds-base security update (Moderate)
Description: 389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), when the password of a LDAP user has been changed and audit logging is enabled, saves the new password to the log in plain text, which allows remote authenticated users to read the password.
Family: unix Class: patch
Reference(s): ELSA-2012:0997-01
CVE-2012-2678
CVE-2012-2746
Version: 13
Platform(s): Oracle Linux 6
Product(s): 389-ds-base
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:27822
 
Oval ID: oval:org.mitre.oval:def:27822
Title: DEPRECATED: ELSA-2012-0997 -- 389-ds-base security update (moderate)
Description: [1.2.10.2-18] - Resolves: Bug 830001 - unhashed#user#password visible after changing password -- patch 0020 disallows users' direct modify on unhashed#user#password [1.2.10.2-17] - Resolves: Bug 830001 - unhashed#user#password visible after changing password -- patch 0019 fixes deref issue. [1.2.10.2-16] - Resolves: Bug 830001 - unhashed#user#password visible after changing password - Resolves: Bug 830256 - Audit log - clear text password in user changes
Family: unix Class: patch
Reference(s): ELSA-2012-0997
CVE-2012-2678
CVE-2012-2746
Version: 4
Platform(s): Oracle Linux 6
Product(s): 389-ds-base
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 42
Application 12
Os 2

OpenVAS Exploits

Date Description
2012-07-30 Name : CentOS Update for 389-ds-base CESA-2012:0997 centos6
File : nvt/gb_CESA-2012_0997_389-ds-base_centos6.nasl
2012-06-22 Name : RedHat Update for 389-ds-base RHSA-2012:0997-01
File : nvt/gb_RHSA-2012_0997-01_389-ds-base.nasl

Nessus® Vulnerability Scanner

Date Description
2014-11-08 Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2012-1041.nasl - Type : ACT_GATHER_INFO
2013-07-12 Name : The remote Oracle Linux host is missing one or more security updates.
File : oraclelinux_ELSA-2012-0997.nasl - Type : ACT_GATHER_INFO
2012-08-01 Name : The remote Scientific Linux host is missing one or more security updates.
File : sl_20120620_389_ds_base_on_SL6_x.nasl - Type : ACT_GATHER_INFO
2012-07-11 Name : The remote CentOS host is missing one or more security updates.
File : centos_RHSA-2012-0997.nasl - Type : ACT_GATHER_INFO
2012-06-21 Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2012-0997.nasl - Type : ACT_GATHER_INFO

Sources (Detail)

Source Url
BID http://www.securityfocus.com/bid/54153
CONFIRM http://directory.fedoraproject.org/wiki/Release_Notes
https://bugzilla.redhat.com/show_bug.cgi?id=833482
https://fedorahosted.org/389/ticket/365
HP https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na...
OSVDB http://www.osvdb.org/83329
OVAL https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova...
REDHAT http://rhn.redhat.com/errata/RHSA-2012-0997.html
http://rhn.redhat.com/errata/RHSA-2012-1041.html
SECUNIA http://secunia.com/advisories/49734
XF https://exchange.xforce.ibmcloud.com/vulnerabilities/76595

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
Date Informations
2022-02-04 12:12:14
  • Multiple Updates
2021-05-05 01:10:33
  • Multiple Updates
2021-05-04 12:20:02
  • Multiple Updates
2021-04-22 01:23:45
  • Multiple Updates
2020-05-23 01:48:51
  • Multiple Updates
2020-05-23 00:33:43
  • Multiple Updates
2019-03-19 12:05:00
  • Multiple Updates
2018-06-13 12:02:15
  • Multiple Updates
2017-09-19 09:25:17
  • Multiple Updates
2017-08-29 09:23:50
  • Multiple Updates
2016-06-28 19:09:31
  • Multiple Updates
2016-04-26 21:52:08
  • Multiple Updates
2014-11-08 13:30:11
  • Multiple Updates
2014-02-17 11:10:43
  • Multiple Updates
2013-12-05 17:19:12
  • Multiple Updates
2013-07-20 13:19:14
  • Multiple Updates
2013-05-10 22:40:24
  • Multiple Updates