Impact
The vulnerability is an LDAP injection flaw in HAVELSAN's Liman MYS. Because user input is incorporated into an LDAP query without neutralizing special characters, an attacker can manipulate the query logic. By sending crafted data, the application may execute unintended searches, potentially revealing sensitive directory information such as user listings, attributes, or other confidential data. The flaw falls under CWE‑90 and poses a confidentiality risk.
Affected Systems
HAVELSAN Inc. Liman MYS versions released before release.Master.1107 are affected. Later releases are not known to be vulnerable.
Risk and Exploitability
The CVSS score of 8.8 classifies the vulnerability as high severity, while the EPSS score of <1% indicates a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that a remote attacker could deliver malicious input through a web interface or API that incorporates unvalidated user data into an LDAP query, triggering the injection.
OpenCVE Enrichment