CVE-2002-0045 describes a vulnerability in OpenLDAP versions 2.0 through 2.0.19, affecting products like OpenLDAP on Linux and Red Hat Linux. This flaw allows local users, and anonymous users in earlier versions, to bypass access controls by performing a "replace" action without values, leading to the deletion of non-mandatory attributes that should be protected by ACLs. With a CVSS score of 7.5 (HIGH), this vulnerability is easily exploitable over the network with low attack complexity and no authentication required, potentially leading to partial compromise of confidentiality, integrity, and availability. While there is no known active exploitation, public exploit code, or Metasploit/Nuclei modules, the vulnerability has garnered significant community discussion, indicating awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.0.19CPE matchmatch criteria | cpe:2.3:a:openldap:openldap:*:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:openldap:openldap:2.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:linux:7.0:*:*:*:*:*:*:* | ||
7.1CPE matchmatch criteria | cpe:2.3:o:redhat:linux:7.1:*:*:*:*:*:*:* | ||
7.2CPE matchmatch criteria | cpe:2.3:o:redhat:linux:7.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.