An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass. This may allow any remote unauthenticated user to issue a filter that allows searching for database items they do not have access to, including but not limited to potentially userPassword hashes and other sensitive data.
Conclusion & alert: CVE-2022-1949 is rated Moderate Risk (54.8/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.38%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.59% | 1.38% | +0.80% |
| 2 | 2026-04-14 | 0.68% | 0.59% | -0.09% |
| 3 | 2025-10-29 | — | 0.68% | — |
Full EPSS history (16 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2022-1949 not yet assigned priority: Debian including 1 source packages (389-ds-base), 4 status rows across 4 suites (bookworm, bullseye, sid, trixie): resolved 3, open 1. | https://security-tracker.debian.org/tracker/CVE-2022-1949 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2022-1949 |
suse
|
critical | CVE-2022-1949 severity critical: SUSE including 39 source package names (2.0-14.9:389-ds-2.0.15~git26.1ea6a6803-150400.3.5.1, 2.0-14.9:lib389-2.0.15~git26.1ea6a6803-150400.3.5.1, …), 122 product×package rows across 29 product lines (Container suse/389-ds, SUSE CaaS Platform 4.0, … (29 product lines)): Fixed 122. | https://www.suse.com/security/cve/CVE-2022-1949/ |
ubuntu
|
medium | CVE-2022-1949 medium priority: Ubuntu including 1 source packages (389-ds-base), 13 status rows across 13 suites (bionic, focal, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, upstream, xenial): needs-triage 7, ignored 6. | https://ubuntu.com/security/CVE-2022-1949 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| redhat | 389_directory_server | >= 1.3.0.0, <= 2.0.0 | cpe:2.3:o:redhat:389_directory_server:*:*:*:*:*:*:*:* |
| redhat | directory_server | 11.0 | cpe:2.3:a:redhat:directory_server:11.0:*:*:*:*:*:*:* |
| redhat | directory_server | 12.0 | cpe:2.3:a:redhat:directory_server:12.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux | 8.0 | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux | 9.0 | cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* |
| fedoraproject | fedora | 34 | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* |
| fedoraproject | fedora | 35 | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* |
| fedoraproject | fedora | 36 | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://bugzilla.redhat.com/show_bug.cgi?id=2091781 | Issue Tracking Patch Third Party Advisory |