First published: Tue Mar 29 2005(Updated: )
AS/400 running OS400 5.2 installs and enables LDAP by default, which allows remote authenticated users to obtain OS/400 user profiles by performing a search.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM OS/400 | =5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0899 has a moderate severity rating due to its potential to expose sensitive user profile information.
To mitigate CVE-2005-0899, disable LDAP service on your AS/400 system if it is not required.
CVE-2005-0899 affects IBM OS/400 version 5.2 installations with LDAP enabled.
CVE-2005-0899 exploits the default configuration of LDAP to allow remote authenticated users to query user profiles.
CVE-2005-0899 remains relevant for organizations using outdated IBM OS/400 versions, especially in environments where LDAP is active.