{"api_version":"1","generated_at":"2026-07-23T06:37:34+00:00","cve":"CVE-2015-3230","urls":{"html":"https://cve.report/CVE-2015-3230","api":"https://cve.report/api/cve/CVE-2015-3230.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-3230","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-3230"},"summary":{"title":"CVE-2015-3230","description":"389 Directory Server (formerly Fedora Directory Server) before 1.3.3.12 does not enforce the nsSSL3Ciphers preference when creating an sslSocket, which allows remote attackers to have unspecified impact by requesting to use a disabled cipher.","state":"PUBLISHED","assigner":"redhat","published_at":"2015-10-29 20:59:00","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-254","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1230996","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1230996","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Bug 1230996 – nsSSL3Ciphers preference not enforced server side (regression)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://fedorahosted.org/389/ticket/48194","name":"https://fedorahosted.org/389/ticket/48194","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"#48194 (nsSSL3Ciphers preference not enforced server side (regression))\n     – 389 Project","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168985.html","name":"http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168985.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[SECURITY] Fedora 21 Update: 389-ds-base-1.3.3.13-1.fc21","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://directory.fedoraproject.org/docs/389ds/releases/release-1-3-3-12.html","name":"http://directory.fedoraproject.org/docs/389ds/releases/release-1-3-3-12.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"389 Directory Server - Releases/1.3.3.12","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHBA-2015:1554","name":"MISC:https://access.redhat.com/errata/RHBA-2015:1554","refsource":"MITRE","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/security/cve/CVE-2015-3230","name":"MISC:https://access.redhat.com/security/cve/CVE-2015-3230","refsource":"MITRE","tags":[],"title":"CVE-2015-3230 - Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1232096","name":"MISC:https://bugzilla.redhat.com/show_bug.cgi?id=1232096","refsource":"MITRE","tags":[],"title":"1232096 – (CVE-2015-3230) CVE-2015-3230 389-ds-base: nsSSL3Ciphers preference not enforced server side (regression)","mime":"text/html","httpstatus":"200","archivestatus":"503"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-3230","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-3230","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"3230","vulnerable":"1","versionEndIncluding":"1.3.3.10","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"fedoraproject","cpe5":"389_directory_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T05:39:32.036Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://fedorahosted.org/389/ticket/48194"},{"name":"FEDORA-2015-15128","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168985.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1230996"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://directory.fedoraproject.org/docs/389ds/releases/release-1-3-3-12.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-10-08T00:00:00.000Z","descriptions":[{"lang":"en","value":"389 Directory Server (formerly Fedora Directory Server) before 1.3.3.12 does not enforce the nsSSL3Ciphers preference when creating an sslSocket, which allows remote attackers to have unspecified impact by requesting to use a disabled cipher."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2015-10-29T19:57:01.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://fedorahosted.org/389/ticket/48194"},{"name":"FEDORA-2015-15128","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168985.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1230996"},{"tags":["x_refsource_CONFIRM"],"url":"http://directory.fedoraproject.org/docs/389ds/releases/release-1-3-3-12.html"}]}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2015-3230","datePublished":"2015-10-29T20:00:00.000Z","dateReserved":"2015-04-10T00:00:00.000Z","dateUpdated":"2024-08-06T05:39:32.036Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-10-29 20:59:00","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-254","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:fedoraproject:389_directory_server:*:*:*:*:*:*:*:*","versionEndIncluding":"1.3.3.10","matchCriteriaId":"D55DA2AE-B217-41DF-A14F-8282D1B3808D"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"3230","Ordinal":"1","Title":"CVE-2015-3230","CVE":"CVE-2015-3230","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"3230","Ordinal":"1","NoteData":"389 Directory Server (formerly Fedora Directory Server) before 1.3.3.12 does not enforce the nsSSL3Ciphers preference when creating an sslSocket, which allows remote attackers to have unspecified impact by requesting to use a disabled cipher.","Type":"Description","Title":"CVE-2015-3230"},{"CveYear":"2015","CveId":"3230","Ordinal":"2","NoteData":"2015-10-29","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"3230","Ordinal":"3","NoteData":"2015-10-29","Type":"Other","Title":"Modified"}]}}}