First published: Wed Mar 29 2023(Updated: )
Cleartext Transmission of Sensitive Information vulnerability in ForgeRock Inc. OpenIDM and Java Remote Connector Server (RCS) LDAP Connector on Windows, MacOS, Linux allows Remote Services with Stolen Credentials.This issue affects OpenIDM and Java Remote Connector Server (RCS): from 1.5.20.9 through 1.5.20.13.
Credit: psirt@forgerock.com
Affected Software | Affected Version | How to fix |
---|---|---|
Forgerock Ldap Connector | >=1.5.20.9<1.5.20.14 |
Upgrade to LDAP connector version 1.5.20.14 or later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1656 is a Cleartext Transmission of Sensitive Information vulnerability found in ForgeRock Inc. OpenIDM and Java Remote Connector Server (RCS) LDAP Connector.
CVE-2023-1656 affects OpenIDM and Java Remote Connector Server (RCS) LDAP Connector versions 1.5.20.9 through 1.5.20.14 on Windows, MacOS, and Linux.
CVE-2023-1656 has a severity score of 7.5, which is considered high.
CVE-2023-1656 can be exploited by remote services with stolen credentials, allowing for the cleartext transmission of sensitive information.
To fix CVE-2023-1656, you should update OpenIDM and Java Remote Connector Server (RCS) LDAP Connector to version 1.5.20.15 or later.