« Volver al listado

CVE-2022-45910

Estado: ModificadaMedia (5.3)—

La neutralización incorrecta de elementos especiales utilizados en una vulnerabilidad de consulta LDAP ('Inyección LDAP') en los conectores de autoridad ActiveDirectory y Sharepoint ActiveDirectory de Apache ManifoldCF permite a un atacante manipular las consultas de búsqueda LDAP (DoS, consultas adicionales, manipulación de filtros) durante la búsqueda del usuario, si el nombre de usuario o la cadena de dominio se pasan al servlet UserACL sin validación. Este problema afecta a Apache ManifoldCF versión 2.23 y versiones anteriores.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-45910",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-45910",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-22T21:02:34.665695Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@apache.org",
      "affectedData": [
        {
          "vendor": "Apache Software Foundation",
          "product": "Apache ManifoldCF",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "maven",
              "lessThanOrEqual": "2.23"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2022-12-07T10:15:11.217",
  "references": [
    {
      "url": "https://lists.apache.org/thread/m693p0dq6jvwwvmy2wnhj6k854z0s444",
      "tags": [
        "Mailing List",
        "Vendor Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://lists.apache.org/thread/m693p0dq6jvwwvmy2wnhj6k854z0s444",
      "tags": [
        "Mailing List",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@apache.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-90"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-74"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-74"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper neutralization of special elements used in an LDAP query ('LDAP Injection') vulnerability in ActiveDirectory and Sharepoint ActiveDirectory authority connectors of Apache ManifoldCF allows an attacker to manipulate the LDAP search queries (DoS, additional queries, filter manipulation) during user lookup, if the username or the domain string are passed to the UserACLs servlet without validation.\n\nThis issue affects Apache ManifoldCF version 2.23 and prior versions."
    },
    {
      "lang": "es",
      "value": "La neutralización incorrecta de elementos especiales utilizados en una vulnerabilidad de consulta LDAP ('Inyección LDAP') en los conectores de autoridad ActiveDirectory y Sharepoint ActiveDirectory de Apache ManifoldCF permite a un atacante manipular las consultas de búsqueda LDAP (DoS, consultas adicionales, manipulación de filtros) durante la búsqueda del usuario, si el nombre de usuario o la cadena de dominio se pasan al servlet UserACL sin validación. Este problema afecta a Apache ManifoldCF versión 2.23 y versiones anteriores."
    }
  ],
  "lastModified": "2026-06-17T05:10:58.617",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:manifoldcf:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4D1D815E-3266-49FA-AE97-FDB9996547EE",
              "versionEndIncluding": "2.23"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@apache.org"
}