Univention develops a narrow portfolio centered on the Univention Corporate Server and its education-focused variant, UCS@School, which serve as identity and systems-management platforms for organizational infrastructure. The vendor's vulnerability signal clusters around credential exposure, information disclosure, and access-control misconfigurations—weakness classes reflecting the sensitive role these products play in managing directory services and user access across networked environments. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Univention over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-1010283HIGH Univention Corporate Server univention-directory-notifier 12.0.1-3 and earlier is affected by: CWE-213: Intentional Information Exposure. The impact is: Loss of Confidentiality. Th | Jul 17, 2019 | 7.5 | 24 | NO | NO |
CVE-2023-38994HIGH The 'check_univention_joinstatus' prometheus monitoring script (and other scripts) in UCS 5.0-5 revealed the LDAP plaintext password of the machine account in the process list allo | Oct 31, 2023 | 7.8 | 22 | NO | NO |
CVE-2020-17477MEDIUM Incorrect LDAP ACLs in ucs-school-ldap-acls-master in UCS@school before 4.4v5-errata allow remote teachers, staff, and school administrators to read LDAP password hashes (sambaNTPa | Oct 26, 2023 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Univention.
Media articles that mention a CVE ID that affects a product developed by Univention — matched by CVE ID, not by vendor name.