Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2018-1337

In Apache Directory LDAP API before 1.0.2, a bug in the way the SSL Filter was setup made it possible for another thread to use the connection before the TLS layer has been established, if the connection has already been used and put back in a pool of connections, leading to leaking any information contained in this request (including the credentials when sending a BIND request).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.029
EPSS Ranking 85.9%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 5.0
References
Products affected by CVE-2018-1337


Contact Us

Shodan ® - All rights reserved