CVE-2015-6538

The login page in Epiphany Cardio Server 3.3, 4.0, and 4.1 mishandles authentication requests, which allows remote attackers to conduct LDAP injection attacks, and consequently bypass intended access restrictions, via a crafted URL.
References
Link Resource
http://www.epiphanyhealthdata.com/blog/certresponse Vendor Advisory
https://www.kb.cert.org/vuls/id/630239 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ephiphanyheathdata:cardio_server:3.3:*:*:*:*:*:*:*
cpe:2.3:a:ephiphanyheathdata:cardio_server:4.0:*:*:*:*:*:*:*
cpe:2.3:a:ephiphanyheathdata:cardio_server:4.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2015-12-27 19:59

Updated : 2024-02-28 15:21


NVD link : CVE-2015-6538

Mitre link : CVE-2015-6538

CVE.ORG link : CVE-2015-6538


JSON object : View

Products Affected

ephiphanyheathdata

  • cardio_server