CVE-2022-24670: Any user can run unrestricted LDAP queries against a configuration endpoint
Published Oct 27, 2022
·Updated
An attacker can use the unrestricted LDAP queries to determine configuration entries
Affected Software
9 affected components
ForgeRock Access Management>=6.0.0<=6.0.0.7
ForgeRock Access Management>=6.5.0<=6.5.0.2
ForgeRock Access Management>=6.5.2.1<=6.5.2.3
ForgeRock Access Management>=7.0.0<=7.0.2
ForgeRock Access Management=6.5.1
ForgeRock Access Management=6.5.3
ForgeRock Access Management=6.5.4
ForgeRock Access Management=7.1.0
ForgeRock Access Management=7.1.1
Remediation
Information
Upgrade to the latest versions.
Event History
Oct 27, 2022
CVE Published
via MITRE·04:53 PM
Data Sourced
via MITRE·04:53 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-24670?
CVE-2022-24670 is a vulnerability that allows attackers to use unrestricted LDAP queries to determine configuration entries.
2
What is the severity of CVE-2022-24670?
CVE-2022-24670 has a severity of 6.5 (high).
3
Which software is affected by CVE-2022-24670?
ForgeRock Access Management versions 6.0.0 to 6.0.0.7, 6.5.0 to 6.5.0.2, 6.5.2.1 to 6.5.2.3, 7.0.0 to 7.0.2, 6.5.1, 6.5.3, 6.5.4, 7.1.0, and 7.1.1 are affected by CVE-2022-24670.
4
How can an attacker exploit CVE-2022-24670?
An attacker can exploit CVE-2022-24670 by using unrestricted LDAP queries to determine configuration entries.
5
Is there a fix for CVE-2022-24670?
Yes, ForgeRock has provided fixes for CVE-2022-24670. It is recommended to update to the latest version of ForgeRock Access Management.