First published: Wed May 04 2022(Updated: )
In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query. This can occur during an LDAP search operation when the search filter is processed, due to a lack of proper escaping.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/openldap | 2.4.47+dfsg-3+deb10u7 2.4.57+dfsg-3+deb11u1 2.5.13+dfsg-5 | |
Openldap Openldap | >=2.0<2.5.12 | |
Openldap Openldap | >=2.6.0<2.6.2 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
Netapp H300s Firmware | ||
Netapp H300s | ||
Netapp H500s Firmware | ||
Netapp H500s | ||
Netapp H700s Firmware | ||
Netapp H700s | ||
Netapp H700e Firmware | ||
Netapp H700e | ||
Netapp H410s Firmware | ||
Netapp H410s | ||
Netapp H410c Firmware | ||
Netapp H410c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29155 is a SQL injection vulnerability in OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, allowing SQL statements within an LDAP query.
CVE-2022-29155 occurs when a SQL statement is included in an LDAP search filter, due to a lack of proper escaping.
CVE-2022-29155 has a severity rating of 9.8 (Critical).
OpenLDAP versions 2.x before 2.5.12 and 2.6.x before 2.6.2 are affected by CVE-2022-29155.
Update to OpenLDAP version 2.5.12 or later to fix CVE-2022-29155.