|
Family: Remote file access --> Category: infos
LDAP allows null bases Vulnerability Scan
Vulnerability Scan Summary Check for LDAP null base
Detailed Explanation for this Vulnerability Test
Synopsis :
It is possible to disclose LDAP information.
Description :
Improperly configured LDAP servers will allow the directory BASE
to be set to NULL. This allows information to be culled without
any prior knowledge of the directory structure. Coupled with a
NULL BIND, an anonymous user can query your LDAP server using a
tool such as 'LdapMiner'
Solution:
Disable NULL BASE queries on your LDAP server
Threat Level:
Low / CVSS Base Score : 2
(AV:R/AC:L/Au:NR/C:P/A:N/I:N/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|