CVE-2014-9713

EUVD-2014-9520
The default slapd configuration in the Debian openldap package 2.4.23-3 through 2.4.39-1.1 allows remote authenticated users to modify the user's permissions and other user attributes via unspecified vectors.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 34%
Affected Products (NVD)
VendorProductVersion
openldapopenldap
2.4.23
openldapopenldap
2.4.24
openldapopenldap
2.4.25
openldapopenldap
2.4.26
openldapopenldap
2.4.27
openldapopenldap
2.4.28
openldapopenldap
2.4.29
openldapopenldap
2.4.30
openldapopenldap
2.4.31
openldapopenldap
2.4.32
openldapopenldap
2.4.33
openldapopenldap
2.4.34
openldapopenldap
2.4.35
openldapopenldap
2.4.36
openldapopenldap
2.4.37
openldapopenldap
2.4.38
openldapopenldap
2.4.39
debiandebian_linux
7.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
openldap
bookworm
2.5.13+dfsg-5
fixed
bullseye
2.4.57+dfsg-3+deb11u1
fixed
bullseye (security)
2.4.57+dfsg-3+deb11u1
fixed
sid
2.5.18+dfsg-3
fixed
trixie
2.5.18+dfsg-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
openldap
lucid
not-affected
precise
Fixed 2.4.28-1.1ubuntu4.6
released
trusty
Fixed 2.4.31-1+nmu2ubuntu8.2
released
utopic
ignored
vivid
Fixed 2.4.31-1+nmu2ubuntu12.3
released
Common Weakness Enumeration