PT-2022-3280 · Php+1 · Php Openssl Extension+1
Arseniy Sharoglazov
·
Published
2022-06-16
·
Updated
2023-06-29
·
CVE-2022-31085
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
LDAP Account Manager versions prior to 8.0
Description
The issue is related to the lack of protection for confidential information in the LDAP Account Manager web application. Exploitation of this issue may allow an attacker to obtain LDAP authentication credentials. The problem arises when the PHP OpenSSL extension is not installed or encryption is disabled by configuration, causing session files to include the LDAP user name and password in clear text.
Recommendations
For versions prior to 8.0, install the PHP OpenSSL extension and ensure session encryption is enabled in the LAM main configuration.
For versions prior to 8.0 where an upgrade is not possible, install the PHP OpenSSL extension and make sure session encryption is enabled in LAM main configuration.
Upgrade to version 8.0 or later to resolve the issue.
Exploit
Fix
Missing Encryption of Sensitive Data
Insufficiently Protected Credentials
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ldap Account Manager
Php Openssl Extension