{"id":"CVE-2015-3250","aliases":["GHSA-cx3q-cv6w-mx4h"],"url":"https://o3.security/vulnerability/CVE-2015-3250","summary":"Exposure of Sensitive Information to an Unauthorized Actor in Apache Directory LDAP API","details":"Apache Directory LDAP API before 1.0.0-M31 allows attackers to conduct timing attacks via unspecified vectors.","published":"2017-09-07T13:29:00Z","modified":"2026-04-10T03:45:15.651805Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.directory.api:api-ldap-model","fixedVersion":"1.0.0-M31"}],"fix":null,"references":[{"type":"ADVISORY","url":"http://directory.apache.org/api/#news_1"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2015/07/07/11"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2015/07/07/5"},{"type":"ADVISORY","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1241163"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2015/07/07/11"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2015/07/07/5"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1241163"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-10T03:45:15.651805Z"}}