CVE-2015-1849
AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows attackers to obtain sensitive information via vectors involving logging the LDAP bind credential password when TRACE logging is enabled.
- Affected products
- Red Hat Jboss Enterprise Application Platform
- Redhat Jboss Enterprise Application Platform
- ≤ 6.4.0
- Fix
- Available
- CVSS 3.0
- 5.9 MEDIUM
- EPSS
- 1.7% (75th percentile)
- Weakness
- CWE-200
- NVD status
- Modified
- Published
- 2017-09-19
CVE-2015-1849 at NVD
No indexed exploits for CVE-2015-1849 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2015-1849 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.