CVE-2001-0502

Running Windows 2000 LDAP Server over SSL, a function does not properly check the permissions of a user request when the directory principal is a domain user and the data attribute is the domain password, which allows local users to modify the login password of other users.
Configurations

Configuration 1 (hide)

cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:*

History

20 Nov 2024, 23:35

Type Values Removed Values Added
References () http://www.ciac.org/ciac/bulletins/l-101.shtml - () http://www.ciac.org/ciac/bulletins/l-101.shtml -
References () http://www.securityfocus.com/bid/2929 - () http://www.securityfocus.com/bid/2929 -
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-036 - () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-036 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/6745 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/6745 -

Information

Published : 2001-07-21 04:00

Updated : 2024-11-20 23:35


NVD link : CVE-2001-0502

Mitre link : CVE-2001-0502

CVE.ORG link : CVE-2001-0502


JSON object : View

Products Affected

microsoft

  • windows_2000