PT-2022-3277 · Unknown · Ldap Account Manager

Arseniy Sharoglazov

·

Published

2022-06-27

·

Updated

2022-10-28

·

CVE-2022-31084

CVSS v3.1

9.3

Critical

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LDAP Account Manager versions prior to 8.0
Description The issue is related to the instantiation of objects from arbitrary classes in LDAP Account Manager, allowing an attacker to inject the first constructor argument. This can lead to code execution if non-LAM classes are instantiated that execute code during object creation.
Recommendations For versions prior to 8.0, update to version 8.0 to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable functionality until the update is applied.

Exploit

Fix

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04001
CVE-2022-31084
DSA-5177-1
GHSA-R387-GRJX-QGVW

Affected Products

Ldap Account Manager