{"api_version":"1","generated_at":"2026-07-23T07:37:35+00:00","cve":"CVE-2015-1849","urls":{"html":"https://cve.report/CVE-2015-1849","api":"https://cve.report/api/cve/CVE-2015-1849.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-1849","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-1849"},"summary":{"title":"CVE-2015-1849","description":"AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows attackers to obtain sensitive information via vectors involving logging the LDAP bind credential password when TRACE logging is enabled.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2017-09-19 17:29:00","updated_at":"2017-10-04 17:36:00"},"problem_types":["CWE-200"],"metrics":[],"references":[{"url":"https://github.com/wildfly-security/jboss-negotiation/commit/0dc9d191b6eb1d13b8f0189c5b02ba6576f4722e","name":"https://github.com/wildfly-security/jboss-negotiation/commit/0dc9d191b6eb1d13b8f0189c5b02ba6576f4722e","refsource":"CONFIRM","tags":["Third Party Advisory"],"title":"SECURITY-877 · wildfly-security/jboss-negotiation@0dc9d19 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/wildfly-security/jboss-negotiation/pull/21","name":"https://github.com/wildfly-security/jboss-negotiation/pull/21","refsource":"CONFIRM","tags":["Third Party Advisory"],"title":"[SECURITY-877] WildFLy is Logging LDAP Bind Credential Password for SPNEGO by spolti · Pull Request #21 · wildfly-security/jboss-negotiation · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1199641","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1199641","refsource":"CONFIRM","tags":["Exploit","Issue Tracking","Third Party Advisory"],"title":"1199641 – [GSS](6.4.z) LDAP Bind Credential Password is Logged","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1208580","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1208580","refsource":"CONFIRM","tags":["Issue Tracking","Third Party Advisory"],"title":"Bug 1208580 – CVE-2015-1849 JBoss EAP: LDAP bind password is being logged with TRACE log level","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-1849","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-1849","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"1849","vulnerable":"1","versionEndIncluding":"6.4.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"jboss_enterprise_application_platform","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2015-1849","ASSIGNER":"secalert@redhat.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows attackers to obtain sensitive information via vectors involving logging the LDAP bind credential password when TRACE logging is enabled."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_affected":"=","version_value":"n/a"}]}}]}}]}},"references":{"reference_data":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1199641","refsource":"MISC","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1199641"},{"url":"https://github.com/wildfly-security/jboss-negotiation/commit/0dc9d191b6eb1d13b8f0189c5b02ba6576f4722e","refsource":"MISC","name":"https://github.com/wildfly-security/jboss-negotiation/commit/0dc9d191b6eb1d13b8f0189c5b02ba6576f4722e"},{"url":"https://github.com/wildfly-security/jboss-negotiation/pull/21","refsource":"MISC","name":"https://github.com/wildfly-security/jboss-negotiation/pull/21"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1208580","refsource":"MISC","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1208580"}]}},"nvd":{"publishedDate":"2017-09-19 17:29:00","lastModifiedDate":"2017-10-04 17:36:00","problem_types":["CWE-200"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.2,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:redhat:jboss_enterprise_application_platform:*:*:*:*:*:*:*:*","versionEndIncluding":"6.4.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"1849","Ordinal":"78744","Title":"CVE-2015-1849","CVE":"CVE-2015-1849","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"1849","Ordinal":"1","NoteData":"AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows attackers to obtain sensitive information via vectors involving logging the LDAP bind credential password when TRACE logging is enabled.","Type":"Description","Title":null},{"CveYear":"2015","CveId":"1849","Ordinal":"2","NoteData":"2017-09-19","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"1849","Ordinal":"3","NoteData":"2017-09-19","Type":"Other","Title":"Modified"}]}}}