Description
A LDAP injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticated attacker could generate data in Active Directory using the application account through blind LDAP injection.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-12528 | A LDAP injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticated attacker could generate data in Active Directory using the application account through blind LDAP injection. |
References
| Link | Providers |
|---|---|
| https://www.tenable.com/security/tns-2023-03 |
|
History
Tue, 01 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2025-04-01T14:58:52.164Z
Reserved: 2023-01-24T00:00:00.000Z
Link: CVE-2023-0476
Updated: 2024-08-02T05:10:56.348Z
Status : Modified
Published: 2023-01-26T21:18:09.727
Modified: 2025-04-01T15:15:58.053
Link: CVE-2023-0476
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD