Impact
The vulnerability is an LDAP injection flaw in HAVELSAN Inc.'s Liman MYS application. The code fails to neutralize special characters that form part of an LDAP query, allowing an attacker to alter the query logic. An attacker who submits crafted input can cause the system to execute an unintended search, potentially retrieving sensitive directory entries such as user credentials or confidential information. This falls under CWE‑90 and presents a confidentiality risk by enabling unauthorized disclosure of protected data.
Affected Systems
HAVELSAN Inc. Liman MYS versions released before release.Master.1107 are affected. Newer releases are not known to be vulnerable.
Risk and Exploitability
The CVSS score of 8.8 classifies the vulnerability as high severity, while the EPSS score of <1% indicates a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that a remote attacker could deliver malicious input through a web interface or API that incorporates unvalidated user data into an LDAP query, triggering the injection.
OpenCVE Enrichment