First published: Thu Oct 27 2022(Updated: )
An attacker can use the unrestricted LDAP queries to determine configuration entries
Credit: psirt@forgerock.com
Affected Software | Affected Version | How to fix |
---|---|---|
ForgeRock Access Management | >=6.0.0<=6.0.0.7 | |
ForgeRock Access Management | >=6.5.0<=6.5.0.2 | |
ForgeRock Access Management | >=6.5.2.1<=6.5.2.3 | |
ForgeRock Access Management | >=7.0.0<=7.0.2 | |
ForgeRock Access Management | =6.5.1 | |
ForgeRock Access Management | =6.5.3 | |
ForgeRock Access Management | =6.5.4 | |
ForgeRock Access Management | =7.1.0 | |
ForgeRock Access Management | =7.1.1 |
Upgrade to the latest versions.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-24670 is a vulnerability that allows attackers to use unrestricted LDAP queries to determine configuration entries.
CVE-2022-24670 has a severity of 6.5 (high).
ForgeRock Access Management versions 6.0.0 to 6.0.0.7, 6.5.0 to 6.5.0.2, 6.5.2.1 to 6.5.2.3, 7.0.0 to 7.0.2, 6.5.1, 6.5.3, 6.5.4, 7.1.0, and 7.1.1 are affected by CVE-2022-24670.
An attacker can exploit CVE-2022-24670 by using unrestricted LDAP queries to determine configuration entries.
Yes, ForgeRock has provided fixes for CVE-2022-24670. It is recommended to update to the latest version of ForgeRock Access Management.