PT-2022-10853 · Ibm · Ibm Websphere Application Server Liberty

Published

2022-01-25

·

Updated

2022-01-28

·

CVE-2021-39031

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 22.0.0.1
Description The issue allows a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this and result in granting permission to unauthorized resources.
Recommendations For versions 17.0.0.3 through 22.0.0.1, consider restricting access to LDAP resources until a patch is available. As a temporary workaround, avoid using specially crafted requests that could exploit the LDAP injection vulnerability.

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-39031

Affected Products

Ibm Websphere Application Server Liberty