Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qhvh-68m3-vj6w

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

Unspecified methods in the RACF Connector component before 1.1.1.0 in ForgeRock OpenIDM and OpenICF improperly call the SearchControls constructor with returnObjFlag set to true, which allows remote attackers to execute arbitrary code via a crafted serialized Java object, aka LDAP entry poisoning.

Unspecified methods in the RACF Connector component before 1.1.1.0 in ForgeRock OpenIDM and OpenICF improperly call the SearchControls constructor with returnObjFlag set to true, which allows remote attackers to execute arbitrary code via a crafted serialized Java object, aka LDAP entry poisoning.

EPSS

Процентиль: 83%
0.01888
Низкий

8.1 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 8.1
nvd
около 9 лет назад

Unspecified methods in the RACF Connector component before 1.1.1.0 in ForgeRock OpenIDM and OpenICF improperly call the SearchControls constructor with returnObjFlag set to true, which allows remote attackers to execute arbitrary code via a crafted serialized Java object, aka LDAP entry poisoning.

EPSS

Процентиль: 83%
0.01888
Низкий

8.1 High

CVSS3

Дефекты

CWE-20