Vulnerabilities > Univention

DATE CVE VULNERABILITY TITLE RISK
2023-10-31 CVE-2023-38994 Exposure of Resource to Wrong Sphere vulnerability in Univention Corporate Server 5.0
The 'check_univention_joinstatus' prometheus monitoring script (and other scripts) in UCS 5.0-5 revealed the LDAP plaintext password of the machine account in the process list allowing attackers with local ssh access to gain higher privileges and perform followup attacks.
local
low complexity
univention CWE-668
7.8
2023-10-26 CVE-2020-17477 Insufficiently Protected Credentials vulnerability in Univention Ucs@School
Incorrect LDAP ACLs in ucs-school-ldap-acls-master in UCS@school before 4.4v5-errata allow remote teachers, staff, and school administrators to read LDAP password hashes (sambaNTPassword, krb5Key, sambaPasswordHistory, and pwhistory) via LDAP search requests.
network
low complexity
univention CWE-522
6.5
2019-07-17 CVE-2019-1010283 Information Exposure vulnerability in Univention Corporate Server
Univention Corporate Server univention-directory-notifier 12.0.1-3 and earlier is affected by: CWE-213: Intentional Information Exposure.
network
low complexity
univention CWE-200
7.5