CyberRota Analysis
AI-GeneratedA vulnerability exists in the 389-ds-base due to the use of a hardcoded static initialization vector for AES-CBC and 3DES-CBC encryption in the LDBM backend, which can allow attackers with privileged filesystem access to infer plaintext equality between encrypted entries by analyzing ciphertext blocks. This could lead to potential data exposure risks. Organizations using 389-ds-base should prioritize addressing this issue to safeguard sensitive information against unauthorized access.
Original NVD Description
A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC operations, allowing an attacker with privileged filesystem access to detect plaintext equality across encrypted entries by comparing ciphertext blocks.
Related CVEs
Other vulnerabilities affecting the same vendor(s)