Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-0143


When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all versions of the LDAP connector prior to 1.5.20.9. The LDAP connector is bundled with Identity Management (IDM) and Remote Connector Server (RCS)


Published

2022-09-19T22:15:10.843

Last Modified

2024-11-21T06:37:59.700

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.3 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-284
  • Type: Primary
    CWE-863

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application forgerock ldap_connector < 1.5.20.9 Yes

References