Improper Authorization in OpenLDAP - CVE-2019-13565

 

Improper Authorization in OpenLDAP - CVE-2019-13565

Published: July 30, 2019


Vulnerability identifier: #VU19562
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-13565
CWE-ID: CWE-285
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to incorrect processing of SASL authentication and session encryption in OpenLDAP. After the first SASL bind is completed, the sasl_ssf value is retained for all new non-SASL connections, allowing to bypass ACLs and obtain access by performing simple binds.

Affected software

OpenLDAP
Amazon Linux AMI
Opensuse
Junos OS
openldap (Alpine package)
openldap
Splunk Enterprise
Oracle Blockchain Platform

How to mitigate CVE-2019-13565

Install updates from vendor's website.

OpenLDAP - update to 2.4.48
openldap (Alpine package) - addressed in versions 2.4.48-r0, 2.4.48-r2
Splunk Enterprise - addressed in versions 9.1.6, 9.2.3, 9.3.1
Junos OS - addressed in versions 15.1X49-D230, 17.4R2-S12, 17.4R3-S3, 18.1R3-S11, 18.2X75-D34, 18.2R3-S6, 18.3R2-S4, 18.3R3-S3, 18.4R2-S5, 18.4R3-S4, 19.1R2-S2, 19.1R3-S2, 19.2R1-S5, 19.2R3, 19.3R2-S4, 19.3R3, 19.4R1-S3, 19.4R2-S2, 19.4R3, 20.1R1-S3, 20.1R2, 20.2R1-S1, 20.2R2, 20.3R1
openldap - update to 2.4.40-16.36
Oracle Blockchain Platform - update to 21.1.2

External References

Related Security Bulletins