CVE-2015-1849
Summary
| CVE | CVE-2015-1849 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-09-19 17:29:00 UTC |
| Updated | 2017-10-04 17:36:00 UTC |
| Description | AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows attackers to obtain sensitive information via vectors involving logging the LDAP bind credential password when TRACE logging is enabled. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Jboss Enterprise Application Platform | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SECURITY-877 · wildfly-security/jboss-negotiation@0dc9d19 · GitHub | CONFIRM | github.com | Third Party Advisory |
| [SECURITY-877] WildFLy is Logging LDAP Bind Credential Password for SPNEGO by spolti · Pull Request #21 · wildfly-security/jboss-negotiation · GitHub | CONFIRM | github.com | Third Party Advisory |
| 1199641 – [GSS](6.4.z) LDAP Bind Credential Password is Logged | CONFIRM | bugzilla.redhat.com | Exploit, Issue Tracking, Third Party Advisory |
| Bug 1208580 – CVE-2015-1849 JBoss EAP: LDAP bind password is being logged with TRACE log level | CONFIRM | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.