Vulnerabilities > Univention
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-10-31 | CVE-2023-38994 | Exposure of Resource to Wrong Sphere vulnerability in Univention Corporate Server 5.0 The 'check_univention_joinstatus' prometheus monitoring script (and other scripts) in UCS 5.0-5 revealed the LDAP plaintext password of the machine account in the process list allowing attackers with local ssh access to gain higher privileges and perform followup attacks. | 7.8 |
2023-10-26 | CVE-2020-17477 | Insufficiently Protected Credentials vulnerability in Univention Ucs@School Incorrect LDAP ACLs in ucs-school-ldap-acls-master in UCS@school before 4.4v5-errata allow remote teachers, staff, and school administrators to read LDAP password hashes (sambaNTPassword, krb5Key, sambaPasswordHistory, and pwhistory) via LDAP search requests. | 6.5 |
2019-07-17 | CVE-2019-1010283 | Information Exposure vulnerability in Univention Corporate Server Univention Corporate Server univention-directory-notifier 12.0.1-3 and earlier is affected by: CWE-213: Intentional Information Exposure. | 7.5 |