CVE-2015-5246: Theforeman Foreman

High severity, CVSS 8.1. EPSS: 1.4% chance of exploitation in the next 30 days.

The LDAP Authentication functionality in Foreman might allow remote attackers with knowledge of old passwords to gain access via vectors involving the password lifetime period in Active Directory.

Affected products

Published 2017-10-06. Last modified 2026-06-17.