PT-2022-27680 · Apache · Apache Manifoldcf

4Ra1N

·

Published

2022-12-07

·

Updated

2025-04-22

·

CVE-2022-45910

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache ManifoldCF versions 2.23 and prior versions
Description The issue is related to improper neutralization of special elements used in an LDAP query, also known as 'LDAP Injection'. This allows an attacker to manipulate the LDAP search queries, potentially leading to denial of service (DoS), execution of additional queries, or filter manipulation during user lookup. The vulnerability occurs when the username or the domain string are passed to the UserACLs servlet without validation in the ActiveDirectory and Sharepoint ActiveDirectory authority connectors of Apache ManifoldCF.
Recommendations For Apache ManifoldCF versions 2.23 and prior, update to a version that includes the fix for this issue. As a temporary workaround, consider validating the username and domain string before passing them to the UserACLs servlet to prevent LDAP injection attacks. Restrict access to the UserACLs servlet to minimize the risk of exploitation.

Fix

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2022-45910

Affected Products

Apache Manifoldcf