Vulnerabilities > Univention > Univention Corporate Server > 5.0

DATE CVE VULNERABILITY TITLE RISK
2023-10-31 CVE-2023-38994 Exposure of Resource to Wrong Sphere vulnerability in Univention Corporate Server 5.0
The 'check_univention_joinstatus' prometheus monitoring script (and other scripts) in UCS 5.0-5 revealed the LDAP plaintext password of the machine account in the process list allowing attackers with local ssh access to gain higher privileges and perform followup attacks.
local
low complexity
univention CWE-668
7.8
2019-07-17 CVE-2019-1010283 Information Exposure vulnerability in Univention Corporate Server
Univention Corporate Server univention-directory-notifier 12.0.1-3 and earlier is affected by: CWE-213: Intentional Information Exposure.
network
low complexity
univention CWE-200
7.5