vendor:
Directory Server
by:
N/A
N/A
CVSS
N/A
Denial of Service
N/A
CWE
Product Name: Directory Server
Affected Version From: Red Hat Directory Server 7.1
Affected Version To: Red Hat Directory Server 8
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
N/A
Red Hat Directory Server Denial of Service Vulnerability
Red Hat Directory Server is prone to a denial-of-service vulnerability because the server fails to handle specially crafted search patterns. An attacker can exploit this issue to consume CPU resources with one search request, effectively blocking additional search requests from executing. Legitimate users may be prevented from authenticating to network resources that use the affected server for authentication.
Mitigation:
Upgrade to the latest version of Red Hat Directory Server.