Running Windows 2000 LDAP Server over SSL, a function does not properly check the permissions of a user request when the directory principal is a domain user and the data attribute is the domain password, which allows local users to modify the login password of other users.
References
Configurations
History
No history.
Information
Published : 2001-07-21 04:00
Updated : 2018-10-12 21:30
NVD link : CVE-2001-0502
Mitre link : CVE-2001-0502
CVE.ORG link : CVE-2001-0502
JSON object : View
Products Affected
microsoft
- windows_2000
CWE