When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all versions of the LDAP connector prior to 1.5.20.9. The LDAP connector is bundled with Identity Management (IDM) and Remote Connector Server (RCS)
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-15356 | When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all versions of the LDAP connector prior to 1.5.20.9. The LDAP connector is bundled with Identity Management (IDM) and Remote Connector Server (RCS) |
Fixes
Solution
Upgrade to LDAP connector 1.5.20.9 or later or disable the optional StartTLS feature in the LDAP connector.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 29 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: ForgeRock
Published:
Updated: 2025-05-29T15:29:12.450Z
Reserved: 2022-01-07T00:00:00.000Z
Link: CVE-2022-0143
Updated: 2024-08-02T23:18:41.713Z
Status : Modified
Published: 2022-09-19T22:15:10.843
Modified: 2024-11-21T06:37:59.700
Link: CVE-2022-0143
No data.
OpenCVE Enrichment
No data.
EUVD