CVE-2022-0143: LDAP Connector: When startTLS is used then LDAP connector ignores the wrong password
Published Sep 19, 2022
·Updated
When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all versions of the LDAP connector prior to 1.5.20.9. The LDAP connector is bundled with Identity Management (IDM) and Remote Connector Server (RCS)
Affected Software
1 affected component
ForgeRock LDAP Connector<1.5.20.9
Remediation
Information
Upgrade to LDAP connector 1.5.20.9 or later or disable the optional StartTLS feature in the LDAP connector.
Event History
Sep 19, 2022
CVE Published
via MITRE·09:15 PM
Data Sourced
via MITRE·09:15 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-0143.
2
What is the severity of CVE-2022-0143?
The severity of CVE-2022-0143 is critical with a score of 9.8.
3
Which versions of the LDAP connector are affected by CVE-2022-0143?
All versions of the LDAP connector prior to 1.5.20.9 are affected by CVE-2022-0143.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-863 and CWE-284.
5
How can I fix CVE-2022-0143?
To fix CVE-2022-0143, update the LDAP connector to version 1.5.20.9 or later.