ZeroHour

CVE-2026-14969

CVSS 3.1
4.4 medium
EPSS
<1%p1
Published
()
Modified
Description

A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC operations, allowing an attacker with privileged filesystem access to detect plaintext equality across encrypted entries by comparing ciphertext blocks.

Vendors
redhat
Products
directory server, 389 directory server, enterprise linux
Weakness
CWE-329
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.