Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2015-3250

21
FAUCET Score

CVE-2015-3250 describes a timing attack vulnerability in Apache Directory LDAP API versions prior to 1.0.0-M31. This high-severity vulnerability (CVSS 7.5) allows remote attackers to potentially extract sensitive information due to timing differences in responses, without requiring user interaction. While the potential impact is high confidentiality loss, there is currently no public exploit code available, nor has it been observed in active exploitation or garnered significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.0.0CPE matchmatch criteria
cpe:2.3:a:apache:directory_ldap_api:*:m30:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

7.5HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.0

Exploit Intelligence

EPSS Score
5.08%
Probability of exploitation in next 30 days
EPSS Percentile
91.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0508 is in the 85th percentile among its peer group of 51,485 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

mavenpatch availablevia ghsa
Product: org.apache.directory.api:api-ldap-modelFixed in: 1.0.0-M31

Vendor Advisories (1)

mavenGHSA-cx3q-cv6w-mx4hhigh

Exposure of Sensitive Information to an Unauthorized Actor in Apache Directory LDAP API

May 17, 2022

References

directory.apache.org / api
Vendor Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
openwall.com / lists/oss-security/2015/07/07/11
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2015/07/07/5
Mailing ListThird Party Advisory