Known vulnerabilities in sssd (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:sssd_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 16
Public exploits: 4
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting sssd (Red Hat package) sssd (Red Hat package) is affected by 16 known vulnerabilities: 2 high, 10 medium, 4 low Critical High Medium Low

Vulnerabilities (16)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU117689 - Improper Privilege Management
CVE-2025-11561
CWE-269 Medium
No
No
1.16.5-10.el7_9.17, 2.2.3-20.el8_2.3, 2.4.0-9.el8_4.4, 2.9.4-5.el8_10.3, 2.9.7-4.el9_7.1 28.10.2025 SB2025102811
SB2025102813
SB2025102814
and 35 more
#VU88857 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2023-3758
CWE-362 Medium
No
No
2.6.2-4.el8_6.3, 2.8.2-4.el8_8.2, 2.8.2-5.el9_2.4, 2.9.4-3.el8_10, 2.9.4-6.el9_4 19.04.2024 SB2024041945
SB2024041946
SB2024041947
and 19 more
#VU71473 - Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CVE-2022-4254
CWE-90 High
No
No
1.16.5-10.el7_9.15, 2.2.0-19.el8_1.3, 2.2.3-20.el8_2.2 24.01.2023 SB2023012437
SB2023012440
SB2023012457
and 13 more
#VU56000 - Command injection
CVE-2021-3621
CWE-77 Medium
No
No
1.16.5-10.el7_9.10, 2.2.0-19.el8_1.2, 2.2.3-20.el8_2.1, 2.4.0-9.el8_4.2 20.08.2021 SB2021082002
SB2021082206
SB2021083125
and 19 more
#VU50040 - Heap-based Buffer Overflow
CVE-2021-3156
CWE-122 Low
Available
Exploited
2.3.0-9.el8 26.01.2021 SB2021012632
SB2021012633
SB2021012634
and 55 more
#VU49845 - Insufficient Verification of Data Authenticity
CVE-2020-25686
CWE-345 Low
Available
No
2.3.0-9.el8 20.01.2021 SB2021012070
SB20210120108
SB20210120122
and 27 more
#VU49844 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2020-25685
CWE-327 Low
Available
No
2.3.0-9.el8 20.01.2021 SB2021012070
SB20210120107
SB20210120122
and 27 more
#VU49843 - Insufficient Verification of Data Authenticity
CVE-2020-25684
CWE-345 Low
Available
No
2.3.0-9.el8 20.01.2021 SB2021012070
SB20210120106
SB20210120122
and 27 more
#VU241 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2016-2118
CWE-300 High
No
No
1.9.2-82.12.el6_4 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 25 more
#VU240 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2016-2115
CWE-300 Medium
No
No
1.9.2-82.12.el6_4 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 24 more
#VU239 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2016-2114
CWE-300 Medium
No
No
1.9.2-82.12.el6_4 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 11 more
#VU238 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2016-2113
CWE-300 Medium
No
No
1.9.2-82.12.el6_4 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 16 more
#VU237 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2016-2112
CWE-300 Medium
No
No
1.9.2-82.12.el6_4 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 24 more
#VU236 - Authentication Bypass by Spoofing
CVE-2016-2111
CWE-290 Medium
No
No
1.9.2-82.12.el6_4 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 25 more
#VU235 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2016-2110
CWE-300 Medium
No
No
1.9.2-82.12.el6_4 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 25 more
#VU234 - Resource exhaustion
CVE-2015-5370
CWE-400 Medium
No
No
1.9.2-82.12.el6_4 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 22 more