PT-2022-10853 · Ibm · Ibm Websphere Application Server Liberty
Published
2022-01-25
·
Updated
2022-01-28
·
CVE-2021-39031
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 22.0.0.1
Description
The issue allows a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this and result in granting permission to unauthorized resources.
Recommendations
For versions 17.0.0.3 through 22.0.0.1, consider restricting access to LDAP resources until a patch is available. As a temporary workaround, avoid using specially crafted requests that could exploit the LDAP injection vulnerability.
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Websphere Application Server Liberty