| Vulnerability Name: | CVE-2022-31088 (CCN-229885) | ||||||||||||
| Assigned: | 2022-06-27 | ||||||||||||
| Published: | 2022-06-27 | ||||||||||||
| Updated: | 2022-07-07 | ||||||||||||
| Summary: | LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the user name field at login could be used to enumerate LDAP data. This is only the case for LDAP search configuration. This issue has been fixed in version 8.0. | ||||||||||||
| CVSS v3 Severity: | 5.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) 4.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
5.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||
| Vulnerability Type: | CWE-74 | ||||||||||||
| Vulnerability Consequences: | Data Manipulation | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2022-31088 Source: XF Type: UNKNOWN lam-cve202231088-ldap-injection(229885) Source: MISC Type: Patch, Third Party Advisory https://github.com/LDAPAccountManager/lam/commit/f1d5d04952f39a1b4ea203d3964fa88e1429dfd4 Source: CCN Type: LDAP Account Manager GIT Repository Unauthenticated LDAP Injection Source: CONFIRM Type: Third Party Advisory https://github.com/LDAPAccountManager/lam/security/advisories/GHSA-wxf8-9x99-6gp4 Source: DEBIAN Type: Third Party Advisory DSA-5177 Source: CCN Type: Mend Vulnerability Database CVE-2022-31088 | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||