Skip to main content

Improper Handling of Missing Values

CVE-2024-6237

Severity Medium
Score 6.5/10

Summary

A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while sending a specific extended search request, leading to a denial of service.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • LOW
  • NONE
  • HIGH

CWE-230 - Improper Handling of Missing Values

The software does not handle or incorrectly handles when a parameter, field, or argument name is specified, but the associated value is missing, i.e. it is empty, blank, or null.

References

Advisory Timeline

  • Published