Описание
ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacker can perform character-by-character retrieval of password hashes, or retrieve a session token or a private key.
Ссылки
- ExploitPatchVendor Advisory
- ExploitThird Party Advisory
- ExploitPatchVendor Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 13.5.1 (исключая)
cpe:2.3:a:forgerock:openam:*:*:*:*:*:*:*:*
EPSS
Процентиль: 99%
0.88708
Высокий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-74
Связанные уязвимости
github
больше 3 лет назад
ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacker can perform character-by-character retrieval of password hashes, or retrieve a session token or a private key.
EPSS
Процентиль: 99%
0.88708
Высокий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-74