When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all versions of the LDAP connector prior to 1.5.20.9. The LDAP connector is bundled with Identity Management (IDM) and Remote Connector Server (RCS)
References
Link | Resource |
---|---|
https://backstage.forgerock.com/downloads/browse/idm/featured/connectors | Patch Vendor Advisory |
https://backstage.forgerock.com/knowledge/kb/article/a11380515 | Patch Vendor Advisory |
Configurations
Information
Published : 2022-09-19 15:15
Updated : 2022-09-21 11:27
NVD link : CVE-2022-0143
Mitre link : CVE-2022-0143
JSON object : View
CWE
CWE-863
Incorrect Authorization
Products Affected
forgerock
- ldap_connector