First published: Mon Sep 19 2022(Updated: )
When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all versions of the LDAP connector prior to 1.5.20.9. The LDAP connector is bundled with Identity Management (IDM) and Remote Connector Server (RCS)
Credit: psirt@forgerock.com
Affected Software | Affected Version | How to fix |
---|---|---|
Forgerock Ldap Connector | <1.5.20.9 |
Upgrade to LDAP connector 1.5.20.9 or later or disable the optional StartTLS feature in the LDAP connector.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-0143.
The severity of CVE-2022-0143 is critical with a score of 9.8.
All versions of the LDAP connector prior to 1.5.20.9 are affected by CVE-2022-0143.
The CWE ID for this vulnerability is CWE-863 and CWE-284.
To fix CVE-2022-0143, update the LDAP connector to version 1.5.20.9 or later.