PT-2022-3280 · Php+1 · Php Openssl Extension+1

Arseniy Sharoglazov

·

Published

2022-06-16

·

Updated

2023-06-29

·

CVE-2022-31085

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions LDAP Account Manager versions prior to 8.0
Description The issue is related to the lack of protection for confidential information in the LDAP Account Manager web application. Exploitation of this issue may allow an attacker to obtain LDAP authentication credentials. The problem arises when the PHP OpenSSL extension is not installed or encryption is disabled by configuration, causing session files to include the LDAP user name and password in clear text.
Recommendations For versions prior to 8.0, install the PHP OpenSSL extension and ensure session encryption is enabled in the LAM main configuration. For versions prior to 8.0 where an upgrade is not possible, install the PHP OpenSSL extension and make sure session encryption is enabled in LAM main configuration. Upgrade to version 8.0 or later to resolve the issue.

Exploit

Fix

Missing Encryption of Sensitive Data

Insufficiently Protected Credentials

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

BDU:2022-04004
CVE-2022-31085
DSA-5177-1
GHSA-6M3Q-5C84-6H6J

Affected Products

Ldap Account Manager
Php Openssl Extension