Source |
CVE Liste |
Identifiant |
8288648 |
Date de publication |
2022-12-07 10:15:11 (vue: 2022-12-07 12:07:01) |
Titre |
CVE-2022-45910 |
Texte |
Improper neutralization of special elements used in an LDAP query ('LDAP Injection') vulnerability in ActiveDirectory and Sharepoint ActiveDirectory authority connectors of Apache ManifoldCF allows an attacker to manipulate the LDAP search queries (DoS, additional queries, filter manipulation) during user lookup, if the username or the domain string are passed to the UserACLs servlet without validation. This issue affects Apache ManifoldCF version 2.23 and prior versions. |
Notes |
|
Envoyé |
Oui |
Condensat |
2022 45910 activedirectory additional affects allows apache are attacker authority connectors cve domain dos during elements filter improper injection issue ldap lookup manifoldcf manipulate manipulation neutralization passed prior queries query search servlet sharepoint special string used user useracls username validation version versions vulnerability without |
Tags |
Vulnerability
|
Stories |
|
Move |
|