LDAP null base returns information

Risk Level: Medium risk vulnerability  Medium

Check or Attack Name: LDAP NullBase

Platforms: LDAP
Description:

If LDAP allows a NULL base in an LDAP search, a user can run a search that returns information on namingContexts and supported controls.

Remedy:

Use an access list control to prevent users from dumping the base of the tree or issuing a request without knowing the base object.

References:

X-Force Logo
Know Your Risks